Analysis of LilithBot Malware and Eternity Threat Group
ID: cc1c3c88-071d-5fb0-a54e-f1c0173fd94a
STIX ID: report--cc1c3c88-071d-5fb0-a54e-f1c0173fd94a
Feed Name: Zscaler Security Research Blog
ThreatLabz analyzed LilithBot, a multifunctional malware offered by the Eternity group as Malware-as-a-Service and distributed via Telegram and Tor; LilithBot acts as a botnet with stealer, clipper, and miner modules, persists via startup installation and mutex checks, uses AES-encrypted configuration and fake code-signing certificates to evade detection, and communicates with identified C2 hosts (e.g., 77.73.133.12:4545). The report provides decrypted config values and license keys, network artifacts, sample hashes, MITRE ATT&CK mappings, and sandbox detection notes, enabling defenders to identify and mitigate infected systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
