Auto-Color is a Linux backdoor first observed in late 2024 in intrusions targeting universities and government organizations in North America and Asia. It provides remote operators with host reconnaissance, remote command execution through an interactive shell, file and configuration management, bidirectional file transfer, network proxying, and a self-removal capability. Its command-and-control communications use a custom encrypted binary protocol and challenge-response mechanism.
When executed with root privileges, Auto-Color installs a user-space rootkit through the dynamic loader’s global preloading mechanism. The embedded shared library hooks libc functions to conceal the backdoor’s files and persistence artifacts, impede their inspection or removal, and filter selected connections from the TCP socket table presented through procfs. The rootkit also attempts to disable SELinux enforcement. Auto-Color daemonizes itself, uses locking to limit concurrent execution, and obfuscates embedded strings and configuration data.
The initial infection vector was not established for its earliest observed activity. In April 2025, unknown threat actors exploited CVE-2025-31324 in SAP NetWeaver to deploy Auto-Color against a U.S.-based chemical-sector organization.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
However, prior flaws (CVE-2025-31324) impacting SAP products, including NetWeaver, have been weaponized by China-nexus espionage clusters like UNC5221, UNC5174, and CL-STA-0048, as well as cybercrime groups such as BianLian and RansomExx. In April 2025, unknown threat actors were also observed exploiting the same critical SAP NetWeaver vulnerability to deploy a backdoor called Auto-Color. | In April 2025, unknown threat actors were also observed exploiting the same critical SAP NetWeaver vulnerability to deploy a backdoor called Auto-Color in an attack aimed at a U.S.-based chemicals company.
“analysts observed a likely link to Auto-Color, a Linux backdoor first reported by Palo Alto Networks in late 2024… previously associated with Auto-Color command-and-control infrastructure…” | On Thursday, May 15, 2025, Ivanti disclosed two critical vulnerabilities - CVE-2025-4427 and CVE-2025-4428 - affecting Ivanti Endpoint Manager Mobile (EPMM) version 12.5.0.0 and earlier. These vulnerabilities can be chained to achieve unauthenticated remote code execution (RCE) on exposed systems.
On Thursday, May 15, 2025, Ivanti disclosed two critical vulnerabilities - CVE-2025-4427 and CVE-2025-4428 - affecting Ivanti Endpoint Manager Mobile (EPMM) version 12.5.0.0 and earlier. These vulnerabilities can be chained to achieve unauthenticated remote code execution (RCE) on exposed systems. | “analysts observed a likely link to Auto-Color, a Linux backdoor first reported by Palo Alto Networks in late 2024… previously associated with Auto-Color command-and-control infrastructure…”
Unit 42 has observed post-exploitation activity following the exploitation of CVE-2025-55182... automated scanning for the remote code execution (RCE) vulnerability... The flaw allows unauthenticated attackers to execute arbitrary code on the server via insecure deserialization of malicious HTTP requests.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“analysts observed a likely link to Auto-Color, a Linux backdoor first reported by Palo Alto Networks in late 2024… previously associated with Auto-Color command-and-control infrastructure…”
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Command - 0x100 Auto-color creates a reverse shell... and launches an interactive Bash shell /bin/bash -i . | Command - 0x100 Auto-color creates a reverse shell, allowing a remote server to interact directly with the victim host.
“It is a user-space rootkit that runs inside other dynamically linked processes, attempts to disable SELinux enforcement, hides its own files, and filters the network information returned from /proc/net/tcp.”
Auto-Color encrypts its strings to prevent easy extraction of its functionality. Additionally, it dynamically resolves APIs at runtime, loading libc and retrieving function addresses with dlsym. This makes static detection harder by avoiding direct system calls.
it dynamically resolves APIs at runtime, loading libc and retrieving function addresses with dlsym.
The malware acts as be benign color-enhancement tool and uses common file names like “door,” “egg,” and “log” to disguise itself.
Command - 0xF This command deletes system files and directories associated with the malware, including the /var/log/cross directory and its contents, as well as the modified /etc/ld.so.preload . After cleaning up these files, it terminates the malware itself
When one of these paths is requested, the library builds a filtered copy and returns that file instead of the original procfs entry... removes matching lines, and writes the remaining content to a temporary file.
Auto-color establishes a communication channel with its Command and Control (C2) server using a TCP socket.
“forming a reliable command-and-control (C2) mechanism using server-side Java injection” and repeated use of HTTP GET/curl/wget to retrieve payloads
Command - 0x300 This command lets Auto-color use the infected machine as a proxy, relaying connections between the attacker and a remote target.
While running, Auto-Color repeatedly tries to connect to 146.70.41.178 over TCP port 443... Each attempt included a different 16-byte value and repeated every four to five seconds.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux backdoor that establishes remote-access/C2 connectivity and, when executed with root privileges, installs a user-space LD_PRELOAD rootkit. It uses the rootkit to attempt to disable SELinux enforcement, hide its files and preload configuration, and filter selected connections from /proc/net/tcp.
Linux backdoor that establishes persistence and attempts C2 communication with 146.70.41.178:443. In root context, it installs itself under /var/log/cross and deploys an LD_PRELOAD user-space rootkit that attempts to disable SELinux enforcement, conceals its files and /etc/ld.so.preload, and sanitizes displayed TCP-connection information.
Backdoor deployed by unknown threat actors after exploiting a critical SAP NetWeaver vulnerability in an attack against a U.S.-based chemical company.
A backdoor deployed via exploitation of a critical SAP NetWeaver vulnerability in an attack against a U.S.-based chemicals company.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.