linux-malware icon indicating copy to clipboard operation
linux-malware copied to clipboard

Tracking interesting Linux (and UNIX) malware. Send PRs

Results 250 linux-malware issues
Sort by recently updated
recently updated
newest added

### Area Offensive techniques ### Parent threat Persistence ### Finding http://www.hick.org/code/skape/papers/remote-library-injection.pdf ### Industry reference _No response_ ### Malware reference _No response_ ### Actor reference _No response_ ### Component Linux ###...

new

### Area Defensive tools ### Parent threat _No response_ ### Finding https://izyknows.medium.com/linux-auditd-for-threat-detection-d06c8b941505 ### Industry reference _No response_ ### Malware reference _No response_ ### Actor reference _No response_ ### Component Linux...

missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.003
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1083
missing:tag:T1552.003
missing:tag:T1567
missing:tag:T1573
missing:tag:T1590
missing:tag:T1021.002
missing:tag:T1027.002
missing:tag:T1059.006
missing:tag:T1574.006
missing:tag:T1070.002
missing:tag:T1021.001
missing:tag:T1562.001
missing:tag:Auditd

### Area Defensive tools ### Parent threat Persistence, Privilege Escalation, Defense Evasion ### Finding https://grsecurity.net/tetragone_a_lesson_in_security_fundamentals ### Industry reference _No response_ ### Malware reference _No response_ ### Actor reference _No response_...

confirmed

### Area Defensive tools ### Parent threat Persistence, Defense Evasion, Credential Access, Command and Control ### Finding https://github.com/CiscoCXSecurity/presentations/blob/master/Auditd%20for%20the%20newly%20threatened.pdf ### Industry reference https://github.com/timb-machine/linux-malware/issues/156 https://github.com/timb-machine/linux-malware/issues/418 https://github.com/timb-machine/linux-malware/issues/420 uses:BPF attack:T1036:Masquerading attack:T1070:Indicator Removal on Host...

confirmed

### Area Defensive tools ### Parent threat _No response_ ### Finding https://github.com/alex-cart/LEAF ### Industry reference _No response_ ### Malware reference _No response_ ### Actor reference _No response_ ### Component Linux...

missing:tactics
missing:tag:T1005
missing:tag:T1003.008
missing:tag:T1078.003
missing:tag:T1518
missing:tag:T1548.003

### Area Offensive tools ### Parent threat Persistence ### Finding https://github.com/NixOS/patchelf ### Industry reference attack:T1574.006:Dynamic Linker Hijacking ### Malware reference _No response_ ### Actor reference _No response_ ### Component Linux...

confirmed

### Area Defensive tools ### Parent threat _No response_ ### Finding https://youtu.be/16_EAsYAApI ### Industry reference _No response_ ### Malware reference _No response_ ### Actor reference _No response_ ### Component Linux...

new
missing:tactics

### Area Defensive tools ### Parent threat Persistence, Defense Evasion, Command and Control ### Finding https://github.com/snapattack/bpfdoor-scanner ### Industry reference uses:BPF attack:T1036:Masquerading attack:T1070:Indicator Removal on Host attack:T1205:Traffic Signaling ### Malware reference...

new

### Area Offensive techniques ### Parent threat Persistence, Defense Evasion ### Finding https://2018.zeronights.ru/wp-content/uploads/materials/09-ELF-execution-in-Linux-RAM.pdf ### Industry reference attack:T1620:Reflective Code Loading ### Malware reference _No response_ ### Actor reference _No response_ ###...

confirmed

### Area Defensive tools ### Parent threat Persistence, Defense Evasion ### Finding https://twitter.com/inversecos/status/1527188391347068928 ### Industry reference uses:BPF attack:T1036:Masquerading attack:T1070:Indicator Removal on Host ### Malware reference BPFDoor Tricephalic Hellkeeper Unix.Backdoor.RedMenshen JustForFun...

confirmed