Skip Navigation

New Zero-Detection Variant of Melofee Backdoor from Winnti Strikes RHEL 7.9

blog.xlab.qianxin.com New Zero-Detection Variant of Melofee Backdoor from Winnti Strikes RHEL 7.9

Background On July 27, 2024, XLab's Cyber Threat Insight and Analysis System(CTIA) detected an ELF file named pskt from IP address 45.92.156.166. Currently undetected on VirusTotal, the file triggered two alerts: an Overlay section and a communication domain mimicking Microsoft. Our analysis ident...

New Zero-Detection Variant of Melofee Backdoor from Winnti Strikes RHEL 7.9
0
0 comments