linux-malware icon indicating copy to clipboard operation
linux-malware copied to clipboard

Tracking interesting Linux (and UNIX) malware. Send PRs

Results 250 linux-malware issues
Sort by recently updated
recently updated
newest added

### Area Supply chain attacks ### Parent threat _No response_ ### Finding https://portswigger.net/daily-swig/backdoor-planted-in-php-git-repository-after-server-hack ### Industry reference PHP ### Malware reference _No response_ ### Actor reference _No response_ ### Component _No...

new
missing:tactics
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1021.002
missing:tag:JavaScript

### Area Malware reports ### Parent threat _No response_ ### Finding https://www.intezer.com/blog/malware-analysis/linux-rekoobe-operating-with-new-undetected-malware-samples/ ### Industry reference _No response_ ### Malware reference Rekoobe ### Actor reference APT31 ### Component Linux ### Scenario...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1021.002
missing:tag:T1027.002
missing:tag:T1053.003
missing:tag:T1205
missing:tag:ProcessTreeSpoofing

### Area Malware reports ### Parent threat _No response_ ### Finding https://blog.sekoia.io/walking-on-apt31-infrastructure-footprints/ ### Industry reference https://github.com/timb-machine/linux-malware/issues/480 ### Malware reference Rekoobe TSH https://github.com/timb-machine/linux-malware/issues/481 ### Actor reference APT31 ### Component Linux ###...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1021.002
missing:tag:T1027.002
missing:tag:T1560
missing:tag:T1222
missing:tag:T1548.001

### Area Malware reports ### Parent threat _No response_ ### Finding https://github.com/akamai/akamai-security-research/tree/main/malware/panchan ### Industry reference _No response_ ### Malware reference Pan-chan [/malware/binaries/pan-chan](../tree/main/malware/binaries/pan-chan) ### Actor reference _No response_ ### Component Linux...

new
missing:tactics
ignore:submodule

### Area Malware reports ### Parent threat _No response_ ### Finding https://www.akamai.com/blog/security/new-p2p-botnet-panchan ### Industry reference _No response_ ### Malware reference Pan-chan https://github.com/timb-machine/linux-malware/issues/477 ### Actor reference _No response_ ### Component Linux...

new
missing:tactics

### Area Malware reports ### Parent threat _No response_ ### Finding https://xorl.wordpress.com/2022/06/22/the-forgotten-suaveeyeful-freebsd-software-implant-of-the-equation-group/ ### Industry reference _No response_ ### Malware reference _No response_ ### Actor reference _No response_ ### Component Linux...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.003
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1552.003
missing:tag:T1567
missing:tag:T1573
missing:tag:T1021.002
missing:tag:T1027.002
missing:tag:T1560
missing:tag:Non-persistentStorage
missing:tag:T1222
missing:tag:T1548.001
missing:tag:T1070.006
missing:tag:RedirectionToNull
missing:tag:T1574.007
missing:tag:T1001

### Area Malware reports ### Parent threat _No response_ ### Finding https://www.intezer.com/blog/malware-analysis/hiddenwasp-malware-targeting-linux-systems/ ### Industry reference _No response_ ### Malware reference HiddenWasp ### Actor reference _No response_ ### Component Linux ###...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1491
missing:tag:T1567
missing:tag:T1573
missing:tag:T1021.002
missing:tag:T1027.002
missing:tag:T1053.003
missing:tag:T1560
missing:tag:T1574.006
missing:tag:T1071.002

### Area Supply chain attacks ### Parent threat _No response_ ### Finding https://arstechnica.com/information-technology/2012/09/questions-abound-as-malicious-phpmyadmin-backdoor-found-on-sourceforge-site/ ### Industry reference PHPMyAdmin ### Malware reference _No response_ ### Actor reference _No response_ ### Component _No...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590

### Area Supply chain attacks ### Parent threat _No response_ ### Finding https://dev.horde.org/h/jonah/stories/view.php?channel_id=1&id=155 ### Industry reference Horde Webmail ### Malware reference _No response_ ### Actor reference _No response_ ### Component...

new
missing:tactics
missing:tag:T1048
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1027.002
missing:tag:T1059.006

### Area Malware PoCs ### Parent threat _No response_ ### Finding https://github.com/schrodyn/bad_UDP ### Industry reference _No response_ ### Malware reference _No response_ ### Actor reference _No response_ ### Component Linux...

new
missing:tactics
missing:tag:T1059.006
missing:tag:T1548.003
missing:tag:T1215