Skip to content

[Intel]: https://vms.drweb.com/virus/?i=21004786 #433

@timb-machine

Description

@timb-machine

Area

Malware reports

Parent threat

Persistence, Defense Evasion

Finding

https://vms.drweb.com/virus/?i=21004786

Industry reference

attack:T1205.002:Socket Filters
attack:T1036:Masquerading

Malware reference

BPFDoor
Tricephalic Hellkeeper
Unix.Backdoor.RedMenshen
JustForFun

Actor reference

DecisiveArchitect

Component

Linux

Scenario

No response