Fysbis is a modular Linux backdoor associated with the Sofacy threat group, also known as APT28 or Sednit, and used in cyber espionage operations. It has been observed as both 32-bit and 64-bit ELF binaries and is designed to install on Linux systems with or without root privileges. The malware uses separate controller and plug-in style components, reflecting a backdoor architecture intended for remote tasking on compromised hosts.
Fysbis has been used against targets aligned with Sofacy’s broader espionage priorities, including government and defense-related organizations, with particular historical focus on Eastern European interests. It has been characterized as relatively low in sophistication but operationally effective.
Observed capabilities include process discovery, keylogging, file deletion, and remote shell functionality. Fysbis can collect information about running processes and supports command-and-control communications that may be Base64-encoded. It has also used masquerading to appear as legitimate Linux software or services during installation and persistence. Analysis of later variants showed modest obfuscation improvements, including use of a rolling double-XOR routine to decode embedded configuration and installation data.
Fysbis is notable as one of the better-documented Linux implants in Sofacy’s cross-platform malware ecosystem, complementing the group’s Windows and other platform tooling and underscoring the long-standing use of Linux malware in state-linked intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Since the group’s emergence in 2007, Bitdefender has become familiar with the backdoors used to compromise Windows and Linux targets, such as Coreshell, Jhuhugit and Azzy for the former OS or Fysbis for the latter.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
...the most recent ELF 64-bit binary... demonstrated minor evolution of the threat, most notably in terms of obfuscation... the referenced byte mask is applied to the other byte arrays using a rolling double-XOR algorithm to construct malware installation paths, filenames, and descriptions... The same masking method is also used by the binary to decode malware configuration C2 information...
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
C2 azureon-line[.]com (TCP/80) ... 198.105.125[.]74 (TCP/80) ... mozilla-plugins[.]com (TCP/80) | C2 azureon-line[.]com (TCP/80) ... C2 198.105.125[.]74 (TCP/80) ... C2 mozilla-plugins[.]com (TCP/80) ... The oldest sample... was found to beacon to the domain azureon-line[.]com... The first of the newer samples... beacons to an IP also widely associated with the Sofacy group... The newest sample... introduces a previously unknown command and control beacon to mozilla-plugins[.]com.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that impersonates trusted Linux software components.
Backdoor malware capable of deleting files.
Malware that can Base64-encode command-and-control traffic.
Backdoor malware that collects information about running processes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.