HiddenWasp

MITRE ATT&CK: S0394 View on attack.mitre.org

Aliases: HiddenWasp

First seen
2019-05-29 00:00:00
Malware type
trojan
Family
Malware family
Operating systems
linux
Related IoCs
1 (1 malicious)
Last IoC activity
2026-07-18 12:13:52
Profile updated
2026-07-07 13:46:32

Context

HiddenWasp is a Linux-based Trojan used to target systems for remote control. It comes in the form of a statically linked ELF binary with stdlibc++.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to HiddenWasp (S0394). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample d596acc70426a16760a2b2cc78ca2cc65c5a23bb79316627c0b2e16489bf86c0 2026-07-18 1

Detection coverage

  • 131 Sigma rules

Malware & tools used

  • Local Account (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Dynamic Linker Hijacking (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • RC Scripts (attack-pattern)
  • Rootkit (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)

Reports & references

  • intezer.com — Elf Malware Analysis 101 Linux Threats No Longer An Afterthought (report)
  • cocomelonc.github.io — Linux Hacking 3 (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Hiddenwasp (report)
  • intezer.com — Blog Hiddenwasp Malware Targeting Linux Systems (report)
  • intezer.com — Orbit New Undetected Linux Threat (report)
  • MITRE ATT&CK — S0394 (report)

External references