Researchers and developers published details and tooling that expose how the Ezuri ELF crypter conceals Linux malware in memory and how packed payloads can be recovered. Analysis cited from AT&T Alien Labs described malware using the Ezuri memory loader, which encrypts payloads with AES in CFB mode, stores the key and IV inside the binary, and then decrypts and executes the payload from memory using memfd_create to reduce on-disk artifacts.
A public GitHub project, ezuri_unpack, was released to automate extraction of payloads from Ezuri-packed binaries. The tool is presented as a simple Go-based unpacker built from prior reverse-engineering work and was reportedly tested against a packed Linux.Cephei sample referenced in the Alien Labs research, giving defenders and analysts a practical way to inspect malware hidden by the Ezuri loader.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
A GitHub repository named "ezuri_unpack" was published as a simple unpacking script for the Ezuri ELF Crypter, based on the prior AT&T Alien Labs analysis and tested against a packed Linux.Cephei sample.
Palo Alto Networks Unit 42 published analysis of TeamTNT's Black-T cryptojacking variant targeting exposed Docker APIs, detailing its worm-like propagation, credential theft, and use of Linux memory password scraping tools. The report also identified deployment of an ELF Monero miner named sbin_u and noted TeamTNT's first observed use of zgrab and memory scraping in its tradecraft.
The GitHub repository for Ezuri, described as a simple Linux ELF runtime crypter and memory-loading utility, was publicly present by at least April 26, 2019 based on initial commit timestamps shown in the repository. The project includes source code and build instructions for creating the Ezuri loader.
AT&T Alien Labs researchers Ofer Caspi and Fernando Martinez published analysis of malware using the Ezuri memory loader, documenting that Ezuri-packed payloads use AES-CFB encryption, store the key and IV in the binary, and decrypt and execute payloads via memfd_create.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 51 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
5 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcebleepingcomputer.com
Open sourceunit42.paloaltonetworks.com
Open sourcecybersecurity.att.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.