Umbreon

MITRE ATT&CK: S0221 View on attack.mitre.org

Aliases: Espeon, Umbreon

First seen
2015-04-01 00:00:00
Malware type
backdoor, rootkit
Family
Malware family
Operating systems
linux
Profile updated
2026-07-07 15:44:49

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services

Context

A Linux rootkit that provides backdoor access and hides from defenders.

Detection coverage

  • 36 Sigma rules

Malware & tools used

  • Windows Command Shell (attack-pattern)
  • Rootkit (attack-pattern)
  • Traffic Signaling (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Local Accounts (attack-pattern)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Umbreon (report)
  • Trend Micro — Pokemon Themed Umbreon Linux Rootkit Hits X86 Arm Systems (report)
  • contagiodump.blogspot.com — Rootkit Umbreon Umreon X86 Arm Samples (report)
  • MITRE ATT&CK — S0221 (report)
  • Trend Micro — Pokemon Themed Umbreon Linux Rootkit Hits X86 Arm Systems (report)

External references