Skip to content

Topic

Linux malware

Malicious software built to run on Linux servers and devices, including backdoors, web shells and botnet agents.

Current clusters

security5 publishers

Evooo1Bot turns edge devices into proxies, and most of its exploits predate 2023

Fortinet's analysis of a new Mirai derivative lists ten CVEs; seven carry identifiers from 2007 to 2022. The reverse SOCKS relay is the part operators should read twice.

Perspective Coverage

5 publishers
Builder
Builder 25%
Operator
Operator 63%
Investor
Investor 12%

Reality

Evidence60
Adoption
Insufficient
Hype gap+10
Incentives30
Confidence65
security5 publishers

DPRK operators compiled their backdoor into the victim's own HAProxy build

Rapid7 says the ted backdoor is built into the victim's existing HAProxy 2.8.12 and hooks its filter API, so the load balancer keeps balancing normally while it logs cookies and injects scripts for selected clients.

Perspective Coverage

5 publishers
Builder
Builder 42%
Operator
Operator 53%
Investor
Investor 5%

Reality

Evidence70
Adoption10
Hype gap+20
Incentives35
Confidence66
security7 publishers

Fully patched Magento stores are being backdoored four days ahead of Adobe's next security release

Sansec reproduced an unauthenticated code-execution chain on clean 2.4.7, 2.4.8 and 2.4.9 installs, and the first victim it saw was already on Adobe's newest patch level for its release line.

Perspective Coverage

7 publishers
Builder
Builder 29%
Operator
Operator 63%
Investor
Investor 8%

Reality

Evidence78
Adoption55
Hype gap+15
Incentives55
Confidence75