HyperSSL (ELF)
Aliases: SysUpdate
- First seen
- 2022-03-15 00:00:00
- Malware type
- rat
- Profile updated
- 2026-07-07 14:25:54
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn country_code:vn country_code:ph
Context
HyperSSL, also known as SysUpdate, is a Linux-based remote access tool (RAT) targeting specific sectors in Asia. It is used for covert data extraction and utilizes sophisticated command and control mechanisms.
Detection coverage
- 5 YARA rules
Detection rules
- SEKOIA_Apt_Luckymouse_Sysupdate_Removing_Tool (yara-rule)
- SEKOIA_Backdoor_Lin_Sysupdate (yara-rule)
- SEKOIA_Luckymouse_Sysupdate_Payload (yara-rule)
- SEKOIA_Luckymouse_Sysupdate_Loader (yara-rule)
- SIGNATURE_BASE_APT_MAL_APT27_Rshell_Jul24 (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Hyperssl (report)
- Trend Micro — Iron Tiger Sysupdate Adds Linux Targeting (report)
- x.com — 1933565063736021372 (report)