Auto-Color is a Linux backdoor first observed in late 2024 and used in intrusions targeting government organizations, universities, and at least one chemicals-sector company. It has also been deployed through exploitation of SAP NetWeaver vulnerability CVE-2025-31324. The malware is designed to provide full remote access while maintaining stealth and persistence on compromised Linux systems.
Auto-Color is an ELF64 Linux implant that uses benign-looking names and masquerading techniques to reduce suspicion, including posing as a legitimate PAM-related component. When executed with root privileges, it installs itself persistently, copies its payload under a new name, and deploys a malicious shared library that is force-loaded into processes through the dynamic loader configuration. That library hooks libc-related functionality to protect the malware’s persistence mechanism, hinder removal and inspection, hide files and directory entries, and conceal command-and-control network activity by filtering connection information from system views. The malware also daemonizes itself, enforces single-instance execution, and stores encrypted configuration data that is decrypted at runtime.
For command and control, Auto-Color uses TCP with a custom encrypted binary protocol and a challenge-response style handshake. Supported operator functions include host reconnaissance, interactive reverse shell access, directory enumeration, bidirectional file transfer, configuration retrieval and update, proxying of network traffic, and self-removal. Reconnaissance data collected can include operating system and host details, user context, network information, hardware characteristics, and execution metadata.
Observed targeting has centered on organizations in North America and Asia, particularly government and education entities. Public reporting has also linked Auto-Color activity to exploitation of enterprise software vulnerabilities, including SAP NetWeaver, though attribution to a specific threat actor remains unconfirmed in the supplied facts. The malware’s combination of persistence through loader manipulation, userland hooking, network concealment, and broad remote-access functionality makes it a stealthy and capable Linux post-compromise implant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
However, prior flaws (CVE-2025-31324) impacting SAP products, including NetWeaver, have been weaponized by China-nexus espionage clusters like UNC5221, UNC5174, and CL-STA-0048, as well as cybercrime groups such as BianLian and RansomExx. In April 2025, unknown threat actors were also observed exploiting the same critical SAP NetWeaver vulnerability to deploy a backdoor called Auto-Color. | In April 2025, unknown threat actors were also observed exploiting the same critical SAP NetWeaver vulnerability to deploy a backdoor called Auto-Color in an attack aimed at a U.S.-based chemicals company.
“analysts observed a likely link to Auto-Color, a Linux backdoor first reported by Palo Alto Networks in late 2024… previously associated with Auto-Color command-and-control infrastructure…” | On Thursday, May 15, 2025, Ivanti disclosed two critical vulnerabilities - CVE-2025-4427 and CVE-2025-4428 - affecting Ivanti Endpoint Manager Mobile (EPMM) version 12.5.0.0 and earlier. These vulnerabilities can be chained to achieve unauthenticated remote code execution (RCE) on exposed systems.
On Thursday, May 15, 2025, Ivanti disclosed two critical vulnerabilities - CVE-2025-4427 and CVE-2025-4428 - affecting Ivanti Endpoint Manager Mobile (EPMM) version 12.5.0.0 and earlier. These vulnerabilities can be chained to achieve unauthenticated remote code execution (RCE) on exposed systems. | “analysts observed a likely link to Auto-Color, a Linux backdoor first reported by Palo Alto Networks in late 2024… previously associated with Auto-Color command-and-control infrastructure…”
Unit 42 has observed post-exploitation activity following the exploitation of CVE-2025-55182... automated scanning for the remote code execution (RCE) vulnerability... The flaw allows unauthenticated attackers to execute arbitrary code on the server via insecure deserialization of malicious HTTP requests.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“analysts observed a likely link to Auto-Color, a Linux backdoor first reported by Palo Alto Networks in late 2024… previously associated with Auto-Color command-and-control infrastructure…”
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Command - 0x100 Auto-color creates a reverse shell... and launches an interactive Bash shell /bin/bash -i . | Command - 0x100 Auto-color creates a reverse shell, allowing a remote server to interact directly with the victim host.
Dropping a shared library that hooks libc functions to hide network connections, stop uninstallation, and ensure its activities remain undetected.
Auto-Color encrypts its strings to prevent easy extraction of its functionality. Additionally, it dynamically resolves APIs at runtime, loading libc and retrieving function addresses with dlsym. This makes static detection harder by avoiding direct system calls.
it dynamically resolves APIs at runtime, loading libc and retrieving function addresses with dlsym.
The malware acts as be benign color-enhancement tool and uses common file names like “door,” “egg,” and “log” to disguise itself.
Command - 0xF This command deletes system files and directories associated with the malware, including the /var/log/cross directory and its contents, as well as the modified /etc/ld.so.preload . After cleaning up these files, it terminates the malware itself
The malware deletes its original executable in both cases. However, with root privileges, it preserves the Auto-color binary at /var/log/cross/auto-color .
Auto-color establishes a communication channel with its Command and Control (C2) server using a TCP socket.
“forming a reliable command-and-control (C2) mechanism using server-side Java injection” and repeated use of HTTP GET/curl/wget to retrieve payloads
Command - 0x300 This command lets Auto-color use the infected machine as a proxy, relaying connections between the attacker and a remote target.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor deployed by unknown threat actors after exploiting a critical SAP NetWeaver vulnerability in an attack against a U.S.-based chemical company.
A backdoor deployed via exploitation of a critical SAP NetWeaver vulnerability in an attack against a U.S.-based chemicals company.
Backdoor delivered after exploitation of SAP NetWeaver flaw; used in breach of a U.S. chemicals company (per summary).
Previously undocumented Linux malware providing full remote access; targeted universities and government organizations in North America and Asia (Nov-Dec 2024).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.