linux-malware icon indicating copy to clipboard operation
linux-malware copied to clipboard

Tracking interesting Linux (and UNIX) malware. Send PRs

Results 250 linux-malware issues
Sort by recently updated
recently updated
newest added

### Area Malware reports ### Parent threat _No response_ ### Finding https://blog.malwaremustdie.org/2020/02/mmd-0065-2021-linuxmirai-fbot-re.html ### Industry reference Mirai (by malwaremustdie.org) ### Malware reference _No response_ ### Actor reference _No response_ ### Component...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1059.006
missing:tag:T1574.006
missing:tag:T1003.008
missing:tag:T1205
missing:tag:IRC

### Area Malware reports ### Parent threat _No response_ ### Finding https://blog.malwaremustdie.org/2020/01/mmd-0065-2020-linuxmirai-fbot.html ### Industry reference Mirai (by malwaremustdie.org) ### Malware reference _No response_ ### Actor reference _No response_ ### Component...

new
missing:tactics
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1021.002
missing:tag:T1027.002
missing:tag:T1574.006
missing:tag:T1003.008
missing:tag:T1071.002
missing:tag:IRC

### Area Malware reports ### Parent threat _No response_ ### Finding https://blog.malwaremustdie.org/2016/08/mmd-0056-2016-linuxmirai-just.html ### Industry reference Mirai (by malwaremustdie.org) ### Malware reference _No response_ ### Actor reference _No response_ ### Component...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1574.006
missing:tag:T1003.008
missing:tag:RedirectionToNull
missing:tag:T1205
missing:tag:ProcessTreeSpoofing
missing:tag:T1046
missing:tag:ProcessTreeSpoofingForking
missing:tag:IRC

### Area Malware reports ### Parent threat _No response_ ### Finding https://www.microsoft.com/security/blog/2021/07/22/when-coin-miners-evolve-part-1-exposing-lemonduck-and-lemoncat-modern-mining-malware-infrastructure/ ### Industry reference LemonDuck ### Malware reference _No response_ ### Actor reference _No response_ ### Component _No response_...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1021.002
missing:tag:JavaScript
missing:tag:T1069

### Area Press/academia ### Parent threat _No response_ ### Finding https://securelist.com/top-10-unattributed-apt-mysteries/107676/ ### Industry reference _No response_ ### Malware reference Metador Plexing Eagle wltm ### Actor reference _No response_ ### Component...

new
missing:tactics
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1491
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1027.002
missing:tag:T1560
missing:tag:T1205

### Area Malware reports ### Parent threat _No response_ ### Finding https://www.trendmicro.com/en_gb/research/19/f/cryptocurrency-mining-botnet-arrives-through-adb-and-spreads-through-ssh.html ### Industry reference CoinMiner ### Malware reference _No response_ ### Actor reference _No response_ ### Component _No response_...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.003
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1552.003
missing:tag:T1567
missing:tag:T1573
missing:tag:Non-persistentStorage
missing:tag:T1222
missing:tag:T1548.001
missing:tag:wltm

### Area Malware reports ### Parent threat _No response_ ### Finding https://www.intezer.com/blog/research/acbackdoor-analysis-of-a-new-multiplatform-backdoor/ ### Industry reference _No response_ ### Malware reference ACBackdoor wltm ### Actor reference _No response_ ### Component Linux...

new
missing:tactics
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1021.002
missing:tag:T1027.002
missing:tag:T1053.003
missing:tag:Non-persistentStorage
missing:tag:T1205
missing:tag:T1620
missing:tag:T1001

### Area Malware reports ### Parent threat _No response_ ### Finding https://blog.talosintelligence.com/2018/06/vpnfilter-update.html ### Industry reference VPNFilter ### Malware reference _No response_ ### Actor reference _No response_ ### Component _No response_...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1021.002
missing:tag:T1027.002
missing:tag:Non-persistentStorage
missing:tag:JavaScript
missing:tag:T1215
missing:tag:T1562.004
missing:tag:wltm

### Area Offensive tools ### Parent threat _No response_ ### Finding https://chromium.googlesource.com/linux-syscall-support/ ### Industry reference _No response_ ### Malware reference _No response_ ### Actor reference _No response_ ### Component Linux...

new
missing:tactics
missing:tag:T1048
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573

### Area Offensive techniques ### Parent threat _No response_ ### Finding https://twitter.com/David3141593/status/1575978540868435968 ### Industry reference _No response_ ### Malware reference _No response_ ### Actor reference _No response_ ### Component Linux...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1071.001
missing:tag:T1567
missing:tag:T1573
missing:tag:T1027.002
missing:tag:T1560