Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware LONGLEASH

LONGLEASH

TLP:CLEAR
Family

AI Analysis

No AI analysis yet.

Description

According to Cisco Talos, LONGLEASH is a new version of the previously disclosed SHORTLEASH backdoor, built from the same C++ codebase and compiled for Linux on MIPS using the Boost.Asio asynchronous networking library along with open-source components for protobuf processing and TLS, and it offers extensive proxying and tunneling capabilities such as reverse shells, HTTP/DNS/SOCKS/TCP/ICMP/UDP proxies, SMTP, packet redirection, and the ability to act as an intermediate command and control server while self-removing if tampering is detected.

Details

Type
Unknown
Platforms
Linux
Confidence
80%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.