HiddenWasp
MITRE ATT&CK: S0394 View on attack.mitre.org
Aliases: HiddenWasp
- First seen
- 2019-05-29 00:00:00
- Malware type
- trojan
- Family
- Malware family
- Operating systems
- linux
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-07-18 12:13:52
- Profile updated
- 2026-07-07 13:46:32
Context
HiddenWasp is a Linux-based Trojan used to target systems for remote control. It comes in the form of a statically linked ELF binary with stdlibc++.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to HiddenWasp (S0394). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | d596acc70426a16760a2b2cc78ca2cc65c5a23bb79316627c0b2e16489bf86c0 | 2026-07-18 | 1 |
Detection coverage
- 131 Sigma rules
Malware & tools used
- Local Account (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Dynamic Linker Hijacking (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- RC Scripts (attack-pattern)
- Rootkit (attack-pattern)
- Windows Command Shell (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
Reports & references
- intezer.com — Elf Malware Analysis 101 Linux Threats No Longer An Afterthought (report)
- cocomelonc.github.io — Linux Hacking 3 (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Hiddenwasp (report)
- intezer.com — Blog Hiddenwasp Malware Targeting Linux Systems (report)
- intezer.com — Orbit New Undetected Linux Threat (report)
- MITRE ATT&CK — S0394 (report)