ZeroHour
Malware

Elirks

0 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Tracking Elirks Variants in Japan: Similarities to Previous Attacks

Unit 42 links new Elirks backdoor variants attacking Japanese organizations to 2012 Taiwan attacks, delivered via spear-phishing PDFs exploiting Adobe Flash CVE-2011-0611.

Unit 42 analyzed new Elirks backdoor variants found in an attack on a Japanese business, noting strong similarities to 2012 attacks on Taiwanese ministries. The backdoor retrieves its C2 address from attacker-created accounts on Japanese blog and SNS services. Recent deliveries used an airline e-ticket lure named "E-TKT" with a PDF exploiting Adobe Flash CVE-2011-0611. Shared infrastructure and tactics with the Scarlet Mimic campaign suggest possible ongoing cyber espionage across East Asia.

Palo Alto Unit 42 · 29d agoThreat actor in the wildCVE-2011-0611

MILE TEA: Cyber Espionage Campaign Targets Asia Pacific Businesses and Government Agencies

Unit 42 names MILE TEA, a cyber-espionage campaign since 2011 targeting Japanese and Taiwanese businesses and government agencies with e-ticket phishing lures and Elirks-family malware.

Unit 42 tracks the MILE TEA espionage campaign, observed as early as 2011, targeting Japanese trading, petroleum, and mobile companies, a Beijing office of a Japanese public organization, and a Taiwanese government agency. The primary infection vector is spear-phishing emails with attachments, mostly custom executable installers posing as flight e-tickets, dropping Elirks, Micrass, or Logedrut as initial bridgehead malware. Elirks and Logedrut retrieve encrypted C2 addresses from attacker-posted blog articles, decoded with Base64 and TEA or DES ciphers. The campaign's focus shifted from Taiwan to Japan around 2013.

Palo Alto Unit 42 · 29d agoThreat actor in the wild

Related CVEs

  • Remote Code Execution in Adobe Flash Player via Crafted Flash Content
    Adobe Flash Player contains a flaw tracked as CWE-843 that allows remote attackers to execute arbitrary code or crash the application (denial of service) by inducing it to load specially crafted Flash content. Exploitation requires only that a victim's Flash runtime process a malicious SWF file — for example embedded in a document or served by a website — with no authentication involved; related reporting from this era describes waterhole attacks in which compromised websites served Flash exploits to targeted users. A successful attack yields code execution with the privileges of the user running Flash, which for browser-plugin deployments typically means the logged-in desktop user. Anyone running affected Adobe Flash Player is affected; CISA's listing does not enumerate specific vulnerable versions, and the product line is end-of-life. Exploitation is confirmed: the flaw was added to CISA's KEV catalog on 2022-03-03, EPSS assigns a 99.4% 30-day exploitation probability (100th percentile), and no public proof-of-concept is known.
    · Adobe Flash Player KEVmass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.