LINUX  

Advanced Espionage Tool  Adware  AI  Android  APP  APPX file  ATM Malware  Backdoor  Banking  Bookit  Bot  BotNet  Code-injection  CoinMiners  Crypt  Cryptocurrency  Cryptojacking  CyberSpy  Data Wiper  DDoS  DEAMON  Destructive Malware  DNS Backdoor  Downloader  Driver  Droper  EDR and AV Killer  ELF   ENGINE  Espionage  Exploit  Families  Fileless  FRAMEWORK  FUD Engine  Go  GPT  GPU  GRU Malware  HTML  ICS  InfoStealer  Injector  iOS  IoT  IRC  ISS   Java  JavaScipt  JSON  Keylogger  Killer  Kit  LINUX  Loader  Maas  MacOS  Macro  Malware  Military Malware  Miner  Mobil  MultiOS  nmp  OS  OSX   OT malware  P2P virus  Password STEALER  Pay-per-install (PPI)  PoS Malware  PowerShell  Program  PyPI   Python  QR trojan  Ransom  Raspberry  RAT  Roque  Rootkit  SMS  Spy  Spyware  SQL Malware  Stealer  SymbOS  Tool  Trojan  TV  UEFI bootkit  USB  Utility  VBA Macro  VBE  VBS  VHD malware  Virus  Vishing toolset  VMware ESXi  Windows  Wipper  WM virus  Worm  Wrapper 

22.05.26 Showboat Introducing Showboat: A new malware family taunts defenses and targets international telecom firms MALWARE LINUX

14.01.26

VoidLink

Unveiling VoidLink – A Stealthy, Cloud-Native Linux Malware Framework

MALWARE

Linux

22.08.25

VShell

The Silent, Fileless Threat of VShell

MALWARE

Linux

20.08.25

DripDropper

Patching for persistence: How DripDropper Linux malware moves through the cloud

MALWARE

Linux

16.04.25

SNOWLIGHT

According to sysdig, SNOWLIGHT is used as a dropper for its fileless payload (vshell). 

MALWARE

Linux

02.04.25

Outlaw

Outlaw Linux Malware: Persistent, Unsophisticated, and Surprisingly Effective

MALWARE

Linux

26.02.25

Auto-Color

Auto-Color: An Emerging and Evasive Linux Backdoor

MALWARE

Linux

18.02.25

ELF/Sshdinjector.A!tr

Analyzing ELF/Sshdinjector.A!tr with a Human and Artificial Analyst

MALWARE

Linux

21.11.24

WolfsBane

Unveiling WolfsBane: Gelsemium’s Linux counterpart to Gelsevirine

MALWARE

LINUX BACKDOOR

08.11.24

CRON#TRAP

CRON#TRAP: Emulated Linux Environments as the Latest Tactic in Malware Staging

MALWARE

LINUX  

27.10.24

FASTCash 

Analysis of a newly discovered Linux based variant of the DPRK attributed FASTCash malware along with background information on payment switches used in financial networks. 

MALWARE

LINUX

14.09.24

Hadooken 

Hadooken Malware Targets Weblogic Applications

MALWARE

Linux

25.08.24

sedexp

Unveiling "sedexp": A Stealthy Linux Malware Exploiting udev Rules

MALWARE

Linux

15.06.24

DISGOMOJI

DISGOMOJI Malware Used to Target Indian Government

MALWARE

Linux

28.02.24

Cyclops Blink

Modular malware framework targeting SOHO network devices

MALWARE

Linux

12.01.24

FBot 

Exploring FBot | Python-Based Malware Targeting Cloud and Payment Services

MALWARE

Linux

27.12.23

SALTWATER

According to Mandiant, SALTWATER is a module for the Barracuda SMTP daemon (bsmtpd) that has backdoor functionality. SALTWATER can upload or download arbitrary files, execute commands, and has proxy and tunneling capabilities.

MALWARE

Linux

27.12.23

SEASPY

According to CISA, this malware is a persistent backdoor that masquerades as a legitimate Barracuda Networks service. The malware is designed to listen to commands received from the Threat Actor’s Command-and-Control through TCP packets

MALWARE

Linux

11.12.23

KEYPLUG

With KEYPLUG, China’s RedGolf Spies On, Steals From Wide Field of Targets

MALWARE

Linux

22.11.23

Kinsing

CVE-23-46604 (Apache ActiveMQ) Exploited to Infect Systems With Cryptominers and Rootkits

MALWARE

Linux

14.11.23

XorDdos

Linux DDoS C&C Malware

MALWARE

Linux

02.11.23

Mozi

P2P Botnets: Review - Status - Continuous Monitoring

MALWARE

Linux

28.10.23

StripedFly

It’s just another cryptocurrency miner… Nobody would even suspect the mining malware was merely a mask, masquerading behind an intricate modular framework that supports both Linux and Windows.

MALWARE

Linux

17.10.23

Poseidon

Part of Mythic C2, written in Golang. 

MALWARE

Linux

13.10.23

PerlBot

ShellBot DDoS Malware Installed Through Hexadecimal Notation Addresses

MALWARE

Linux

19.09.23

SprySOCKS

Earth Lusca Employs New Linux Backdoor, Uses Cobalt Strike for Lateral Movement

MALWARE

Linux

07.08.23

SkidMap 

While analyzing the latest logs of our honeypot located in central Europe, we found a rather interesting entry that repeated again less than two weeks later.

MALWARE

Linux

02.08.23

h2miner

A Post-exploitation Look at Coinminers Abusing WebLogic Vulnerabilities

MALWARE

Linux

02.08.23

Rekoobe

A Trojan for Linux intended to infect machines with the SPARC architecture and Intel x86, x86-64 computers.

MALWARE

Linux

22.07.23

BianLian

BianLian Ransomware Expanding C2 Infrastructure and Operational Tempo

MALWARE

Linux

07.07.23

Tsunami

8220 Gang Deploys a New Campaign with Upgraded Techniques

MALWARE

LINUX

24.06.23

reptile

Operation Earth Berberoka

MALWARE

Linux

24.06.23

Kaiten

According to netenrich, Kaiten is a Trojan horse that opens a back door on the compromised computer that allows it to perform other malicious activities.

MALWARE

Linux

07.06.23

KEYPLUG

The Next Gen PlugX/ShadowPad? A Dive into the Emerging China-Nexus Modular Trojan, Pangolin8RAT (slides)

MALWARE

Linux

15.05.23

BPFDoor 

BPFDoor is a passive backdoor used by a China-based threat actor.

MALWARE

Linux

28.04.23

PingPull 

Chinese Alloy Taurus Updates PingPull Malware

MALWARE

Linux

6.4.23 

Mélofée

Mélofée: a new alien malware in the Panda's toolset targeting Linux hosts

MALWARE

Linux

23.03.23

VIRTUALPITA (LINUX)

Mandiant discovered two (2) additional VIRTUALPITA samples listening on TCP port 7475 that were persistent as an init.d startup service on Linux vCenter systems. To disguise themselves, the binaries shared the name of the legitimate binary ksmd. KSMD (Kernel Same-Page Merging Daemon) is normally in charge of memory-saving de-duplication on Linux and would not be listening on this port. 

MALWARE

LINUX

23.03.23

ShellBot

ShellBot Malware Being Distributed to Linux SSH Servers

MALWARE

Linux

02.03.23

Rshell

Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users

MALWARE

Linux

20.01.23

BOLDMOVE

Suspected Chinese hackers exploited a recently disclosed FortiOS SSL-VPN vulnerability as a zero-day in December, targeting a European government and an African MSP with a new custom 'BOLDMOVE' Linux and Windows malware.

MALWARE

Linux malware

07.07.22

BPFDoor

BPFDoor is a passive backdoor used by a China-based threat actor. This backdoor supports multiple protocols for communicating with a C2 including TCP, UDP, and ICMP allowing the threat actor a variety of mechanisms to interact with the implant. 

MALWARE

Linux

07.07.22

Symbiote Linux

Symbiote, a new “nearly impossible to detect” Linux malware, targeted financial sectors in Latin America—and the threat actors behind it might have links to Brazil. These findings were revealed in a recent report, a joint effort between the Blackberry Research Team and Dr. Joakim Kennedy, a security researcher with Intezer. 

MALWARE

Linux

14.06.22

Syslogk 

Rootkits are dangerous pieces of malware. Once in place, they are usually really hard to detect. Their code is typically more challenging to write than other malware, so developers resort to code reuse from open source projects.

MALWARE

Linux

14.06.22

Rekoobe

A Trojan for Linux intended to infect machines with the SPARC architecture and Intel x86, x86-64 computers. The Trojan’s configuration data is stored in a file encrypted with XOR algorithm 

MALWARE

Linux

20.05.22

XorDdos

XorDdos depicts the trend of malware increasingly targeting Linux-based operating systems, which are commonly deployed on cloud infrastructures and Internet of Things (IoT) devices. By compromising IoT and other internet-connected devices, XorDdos amasses botnets that can be used to carry out distributed denial-of-service (DDoS) attacks.

MALWARE

Linux


Linux / Cdorked

Linux / Cdorked

Linux / Clapzok.A

Linux / Ebury

Linux / Onimiki

Linux / Roopre.A

Linux / Tsunami.NAS

Linux.Adore.Worm

Linux.Apaback

Linux.Backdoor.Kaiten

Linux.Backdoor.Rexob

Linux.Cdorked

Linux.Ddssh

Linux.DoS.tfn2k.tfn

Linux.Fokirtor

Linux.Hijacker.Worm

Linux.Chapro

Linux.Cheese.Worm

Linux.Jac.8759

Linux.Kaiten

Linux.Lion.Worm

Linux.Mare

Linux.Mare.K

Linux.Millen.Worm

Linux.Netweird

Linux.Perbot

Linux.Phalax

Linux.Plupii

Linux.Plupii.C

Linux.Psybot

Linux.Ramen.Worm

Linux.RST.B

Linux.Slapper.D

Linux.Slapper.Worm

Linux.Sorso

Linux.Sshdoor

Linux.SSHKit