216.73.216.6

Kiteshield Packer is Being Abused by Linux Cyber Threat Actors

· Published 29/05/2024 10:38 · Modified 29/05/2024 11:30

Export JSON

Essential information

Published
29/05/2024 10:38
Modified
29/05/2024 11:30
Tags
2024-05-29 gafgyt linux packer winnti
Related entities
4 observables, 1 intrusion sets (apt), 10 techniques (mitre), 3 malware

Description

This analysis uncovers the use of Kiteshield by various cybercriminal groups to evade detection on platforms. The researchers reverse-engineered samples from APT group , cybercrime group DarkMosquito, and a script kiddie operation, revealing Kiteshield's anti-debugging techniques, string obfuscation, and encryption methods. Despite the initial excitement over potentially novel threats, the findings highlight cybercriminals adopting Kiteshield to bypass antivirus detection. The report emphasizes the need for improved detection capabilities against this as malware continues evolving.

External references