RotaJakiro is a Linux x86-64 backdoor first publicly identified in 2021, with samples observed since at least 2018. It uses a custom encrypted command-and-control protocol over TCP port 443 that does not use TLS, protecting embedded resources and network traffic with AES, XOR, rotate operations, and ZLIB compression. The backdoor collects device and operating-system information, can steal sensitive information, upload collected data to command-and-control infrastructure, receive and manage files or plugins, and execute functionality supplied through dynamically loaded shared libraries. RotaJakiro implements separate root and non-root persistence and process-watchdog mechanisms. Root-level operation uses Linux service-management persistence and automatic service restart, while non-root operation uses user-level autostart and shell-environment persistence together with mutually monitoring processes that exchange process identifiers through shared memory. It also enforces a single-instance lock and masquerades as Linux system components. Code and protocol similarities have led to an assessment that RotaJakiro is highly likely to be a Linux implementation of the OceanLotus backdoor family. Its initial-access vector, targets, and ultimate operational purpose are not publicly established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
0x1B25503 execute function from a plugin(a aynamic library); 0x1532e65 execute function from a plugin(a aynamic library); 0x25D5082 execute function from a plugin(a aynamic library).
...uses the LoadLibraryExW() function to load additional modules... execute additional plugins by loading the respective DLLs... loaded and executed DLLs in memory during runtime... loads a dynamic library (.dylib file) using dlopen() and obtains a function pointer... using dlopen() and dlsym()... calls LoadLibrary then executes exports from a DLL.
Modify the .bashrc file to create the autostart script for the shell environment.
Depending on the Linux distribution, create the corresponding self-starting script /etc/init/systemd-agent.conf or /lib/systemd/system/sys-temd-agent.service.
RotaJakiro makes a distinction between root/non-root users when implementing persistence features, and different techniques are used for different accounts.
Modify the .bashrc file to create the autostart script for the shell environment.
Depending on the Linux distribution, create the corresponding self-starting script /etc/init/systemd-agent.conf or /lib/systemd/system/sys-temd-agent.service.
RotaJakiro makes a distinction between root/non-root users when implementing persistence features, and different techniques are used for different accounts.
RotaJakiro uses techniques such as dynamic AES, double-layer encrypted communication protocols to counteract binary and network traffic analysis. All sensitive resources in RotaJakiro are encrypted.
The decryption method dec_proc is called 60 times, which is composed of AES and Rotate. The AES decryption entry is AES-256, CBC mode.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
The file name used for the disguise is /bin/systemd/systemd-daemon or /usr/lib/systemd/systemd-daemon. Non-root names include session-dbus and gvfsd-helper.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
...uses the LoadLibraryExW() function to load additional modules... execute additional plugins by loading the respective DLLs... loaded and executed DLLs in memory during runtime... loads a dynamic library (.dylib file) using dlopen() and obtains a function pointer... using dlopen() and dlsym()... calls LoadLibrary then executes exports from a DLL.
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
Some Backdoor.Oldrea samples use standard Base64 + bzip2... gh0st RAT has used Zlib to compress C2 communications data before encrypting it... HOPLIGHT has utilized Zlib compression to obfuscate the communications payload.
The sample communicates with 4 domains on TCP 443 (HTTPS), but the traffic is not of TLS/SSL... RotaJakiro establishes communication with C2 and waits for the execution of commands issued by C2.
RotaJakiro and OceanLotus use separate data structures to hold C2 session information... C2 domain name resolution and session establishment are performed in one function.
RotaJakiro supports a total of 12 instructions... Deliver File/Plugin... Run Plugin_0x39C93E... Run Plugin_0x75A7A2... Run Plugin_0x536D01.
C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding... APT19 HTTP malware variant used Base64 to encode communications to the C2 server... APT33 has used base64 to encode command and control traffic.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a Linux backdoor with code overlap to PeerBlight, particularly around persistence mechanisms and naming conventions, but described as distinct from the recovered sample.
Linux backdoor that uses shared memory for inter-process communication and PID sharing.
Linux backdoor/botnet with C2 communication, host registration, device-information upload capability, and the ability to execute functions from plugins (dynamic libraries). It is assessed as highly likely to be a Linux implementation of OceanLotus.
Linux x64 后门木马,具备较强隐蔽与加密通信能力:样本内资源使用 AES 加密;C2 通信综合使用 AES/XOR/ROTATE 加密与 ZLIB 压缩;支持设备信息上报、敏感信息窃取、文件/插件管理(查询/下载/删除)以及执行插件等能力。具备持久化(root 与非 root 采用不同机制)、进程守护(服务 respawn/Restart=always 或双进程互保)、单实例(文件锁)与结构化 C2 协议。
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.