timb-machine / linux-malware

Tracking interesting Linux (and UNIX) malware. Send PRs
The Unlicense
1.13k stars 91 forks source link

[Intel]: https://pastebin.com/kmmJuuQP #802

Open timb-machine opened 9 months ago

timb-machine commented 9 months ago

Area

Malware source

Parent threat

Defense Evasion, Command and Control

Finding

https://pastebin.com/kmmJuuQP

Industry reference

attack:T1205.002:Socket Filters attack:T1205:Traffic Signaling uses:BPF uses:Non-persistentStorage uses:ProcessTreeSpoofing

Malware reference

BPFDoor /malware/binaries/BPFDoor Unix.Backdoor.RedMenshen

Actor reference

No response

Component

Linux

Scenario

No response