Xnote is a Linux backdoor detected in the wild since at least 2015. It has been associated with Earth Berberoka (also known as GamblingPuppet), including operations against online gambling sites. Xnote has also been deployed on Linux servers during intrusions attributed to the Chinese-linked CL-UNK-1068 cluster, which targeted critical infrastructure, government, technology, telecommunications, and other high-value sectors across Asia. Observed Xnote variants provide remote backdoor functionality, including distributed-denial-of-service capabilities and command execution. Xnote has additionally been observed in attacks against Linux systems in AI research environments, where threat actors exploited public-facing vulnerabilities and misconfigurations to deploy lightweight backdoors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Xnote, a Linux backdoor tied to the group, was reported in March during attacks on critical infrastructure in Asia.
Xnote, a Linux backdoor tied to the group, was reported in March during attacks on critical infrastructure in Asia.
Further, to maintain command-and-control (C2) access and bypass network controls, the actor also deploys modified builds of Fast Reverse Proxy (FRP) and occasionally installs the Xnote Linux backdoor.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux backdoor tied to the group and reportedly used in attacks against Asian critical infrastructure.
Linux backdoor used to provide unauthorized remote access on compromised Linux systems.
Linux backdoor used to maintain persistent remote access and support command-and-control on compromised Linux hosts.
Linux backdoor (first reported 2015) used here primarily for DDoS capabilities plus file operations, reverse shell, port forwarding, and reverse proxy/tunneling tasks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.