timb-machine / timb-machine/linux-malware

[Intel]: https://www.vmware.com/content/dam/digitalmarketing/vmware/en/pdf/docs/vmw-exposing-malware-in-linux-based-multi-cloud-environments.pdf

Open
#101 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

deprecated:template
Dominant language
HTML
Stars
1.2k
Forks
95
PR merge metrics
No merged PRs in 30d

Description

Area

Press/academia

Parent threat

Defense Evasion, Command and Control, Exfiltration, Impact

Finding

https://www.vmware.com/content/dam/digitalmarketing/vmware/en/pdf/docs/vmw-exposing-malware-in-linux-based-multi-cloud-environments.pdf

Industry reference

attack:T1486:Data Encrypted for Impact

Malware reference

XMRig
Hello Kitty
https://github.com/timb-machine/linux-malware/issues/546
REvil
DarkSide
BlackMatter
Defray777
ViceSociety
Erebus
GonnaCry
eChoraix
Sysrv
TeamTNT
Mexalz
Omelette
WatchDog
Kinsing
Cobalt Strike
Vermillion Strike
Merlin
https://github.com/timb-machine/linux-malware/issues/545
https://github.com/timb-machine/linux-malware/issues/547
RedXOR
https://github.com/timb-machine/linux-malware/issues/548
ACBackdoor
https://github.com/timb-machine/linux-malware/issues/549
ELF_Plead

Actor reference

No response

Component

Linux, VMware

Scenario

No response

Scenario variation

Internal enterprise services, Internal specialist services

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the VMware report and the linked malware issues first, then inspect the repository's existing issue and entry conventions. Done means recording this finding consistently with the report, malware references, component, and applicable ATT&CK reference; the issue does not name a file or test to run.

Written by the indexing model from the issue text.

Assessment

Tech stack
linux
Domain
operating-systems, security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.