Umbreon
MITRE ATT&CK: S0221 View on attack.mitre.org
Aliases: Espeon, Umbreon
- First seen
- 2015-04-01 00:00:00
- Malware type
- backdoor, rootkit
- Family
- Malware family
- Operating systems
- linux
- Profile updated
- 2026-07-07 15:44:49
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services
Context
A Linux rootkit that provides backdoor access and hides from defenders.
Detection coverage
- 36 Sigma rules
Malware & tools used
- Windows Command Shell (attack-pattern)
- Rootkit (attack-pattern)
- Traffic Signaling (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Local Accounts (attack-pattern)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Umbreon (report)
- Trend Micro — Pokemon Themed Umbreon Linux Rootkit Hits X86 Arm Systems (report)
- contagiodump.blogspot.com — Rootkit Umbreon Umreon X86 Arm Samples (report)
- MITRE ATT&CK — S0221 (report)
- Trend Micro — Pokemon Themed Umbreon Linux Rootkit Hits X86 Arm Systems (report)