216.73.216.226

Auto-Color: An Emerging and Evasive Linux Backdoor

· Published 25/02/2025 02:46 · Modified 25/02/2025 09:41

Export JSON

Essential information

Published
25/02/2025 02:46
Modified
25/02/2025 09:41
Tags
2025-02-25 auto-color backdoor c2 encryption evasion government library implant linux proxy reverse shell symbiote universities
Related entities
10 observables, 13 techniques (mitre), 2 malware, 3 others

Description

is a newly discovered malware that employs sophisticated techniques. It renames itself to benign-looking filenames, hides remote connections using advanced methods similar to malware, and uses proprietary for communication. The malware installs a malicious to intercept system calls and conceal its network activity. It provides threat actors with full remote access to compromised machines and is difficult to remove. primarily targets and offices in North America and Asia. The malware's protocol includes a simple handshake and encrypted messages for issuing commands. Its capabilities include file operations, network proxying, and creating reverse shells.

External references