Technical advisory
Verified open source
FontOnLake: Previously unknown malware family targeting Linux
Intelligence with traceable provenance. EudorIA retains technical indicators acquired from supported feeds, with source, date and context. Shareable IOCs are available in the STIX feeds; detection and blocking actions require an assessment of validity, confidence and applicability to the customer's environment. Browse STIX feeds
EudorIA operational summary
Priority 55/100
What it means
MISP EudorIA ha pubblicato l'advisory "FontOnLake: Previously unknown malware family targeting Linux". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.
Why it matters
Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.
Recommended actions
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
AudienceITSOCCISO
Text acquired from the source
Evento MISP pubblicato con TLP:CLEAR: FontOnLake: Previously unknown malware family targeting Linux.
- Source
- MISP EudorIA
- Publishing entity
- MISP EudorIA
- Entity type
- Intelligence community
- Area
- Global
- Original language
- it ยท translation not needed
- Publication
- 30/07/2026 02:45
- Sharing
- TLP:CLEAR
- Indicators reported by the source
- 41
- IOCs indexed for lookup
- 0 values within the retention period
- IOCs available in the STIX feed
- 41Last sharing verification: 2026-09-26T09:03:18.449603+00:00
- MISP event
- 5f17a0c6-7b04-4f05-9fda-b5d435a8d6a4
- MITRE ATT&CK
- Boot or Logon Initialization Scripts - T1037, Compromise Client Software Binary - T1554, Deobfuscate/Decode Files or Information - T1140, Fallback Channels - T1008, File Transfer Protocols - T1071.002, File and Directory Discovery - T1083, Hidden Files and Directories - T1564.001, Hide Artifacts - T1564, Kernel Modules and Extensions - T1547.006, Linux and Mac File and Directory Permissions Modification - T1222.002, Modify Authentication Process - T1556, Native API - T1106, Non-Application Layer Protocol - T1095, Obfuscated Files or Information - T1027, Python - T1059.006, Rootkit - T1014, Standard Encoding - T1132.001, Symmetric Cryptography - T1573.001, System Information Discovery - T1082, Unix Shell - T1059.004
- Classification
- Low