Exaramel for Linux is a Linux backdoor associated with the Exaramel malware family. It supports encrypted configuration handling, uses HTTPS for command-and-control communications, and includes command-and-control resiliency by attempting to locate an alternate server when communication errors occur. The malware performs basic host reconnaissance by executing whoami to identify the current user or system owner. It also includes cleanup functionality that can remove its persistence mechanism and delete its configuration data, indicating support for self-maintenance and anti-forensic cleanup. The observed behavior is consistent with a Linux-focused remote access implant designed for post-compromise control, host profiling, and resilient operator communications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux backdoor that runs whoami to identify the system owner.
Linux backdoor that decrypts its configuration file.
Runs whoami to identify the system owner.
Linux backdoor that can remove persistence and delete its configuration file.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.