Pygmy Goat is a Linux backdoor observed on Sophos XG firewall devices and designed to target additional Linux-based systems, including cloud environments. It was discovered exploiting the vulnerable libsophos.so library file to gain initial access and persistence via authentication bypass in CVE-2022-1040. Reporting cited in the content places it among actively updated Linux ELF malware families used against cloud infrastructure, with at least 20 unique sightings in the wild and multiple significant code updates over the last year. The malware has been associated in the reporting context with China-linked activity targeting edge infrastructure, where custom malware was used to maintain persistent remote access and repurpose compromised devices as stealthy proxies. Targeting noted in the content includes government, NGO, healthcare, and transportation sectors in Asia-Pacific. High-confidence behavioral details directly mentioned are Linux backdoor functionality, persistence through rootkit-like use of libsophos.so, exploitation of Sophos firewall devices, and abuse of CVE-2022-1040. The content also identifies Pygmy Goat as a threat defenders should monitor alongside Asnarök and Gh0st RAT in Sophos-related intrusion contexts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pygmy Goat is a Linux backdoor/rootkit that leverages a vulnerable library (libsophos.so) to gain persistence and injects itself into the SSH daemon. It supports remote shells, packet capture, cron job creation, and reverse SOCKS5 proxy tunneling. It uses port knocking and magic bytes for C2 initiation.
Custom malware used by Chinese state-sponsored threat actors for persistent remote access and proxying through compromised edge devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.