GhostPenguin is a Linux backdoor written in C++ and compiled as a 64-bit ELF for x86-64 systems. It is designed for covert remote access, providing operators with command execution through a remote shell and broad file-system control, including file creation, deletion, renaming, reading, writing, timestamp modification, searching by extension, and directory enumeration and management. The malware collects host metadata such as network, operating system, user, architecture, and process information during registration with its command-and-control infrastructure.
GhostPenguin communicates over UDP and uses a custom multi-stage protocol that begins with an unencrypted session setup and then transitions to RC5-encrypted traffic using a server-provided session identifier as the encryption key. It maintains command-and-control through heartbeat messages and implements its own acknowledgment and retransmission logic to improve reliability over UDP. The malware also includes logic to prevent multiple concurrent instances on the same host.
Available reporting characterizes GhostPenguin as a bespoke Linux implant in an apparent early stage of development. Observed code artifacts include unused persistence-related functions and leftover debug elements, indicating ongoing refinement. Its use of encrypted UDP command-and-control, remote shell access, and extensive file-management capabilities makes it suitable for stealthy post-compromise operations on Linux systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
This information includes: LAN IP address Default gateway (obtained via Netlink sockets)
This information includes: LAN IP address Default gateway ... Host name Current username (via whoami command)
After extracting the PID, it invokes kill(pid, 0) to test whether that process is currently active.
The malware collects system information including IP address, gateway, OS version, hostname, and username, and sends it to a C&C server during a registration phase.
Supported commands allow the malware to provide a remote shell via “/bin/sh”, and perform various file and directory operations including creating, deleting, renaming, reading, and writing files, modifying file timestamps, and searching for files by extension.
All C&C communication occurs over UDP port 53. The malware first requests a 16-byte session ID from the server, which is subsequently used as the key for an RC5 encryption algorithm to encrypt all traffic. The malware sends periodic heartbeats to maintain its connection.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-threaded Linux backdoor written in C++ that collects host information, registers with a C2 server, communicates over UDP port 53 using an RC5-encrypted session ID, maintains heartbeats, provides a remote shell via /bin/sh, and supports extensive file and directory operations including create, read, write, delete, rename, timestamp modification, and file searching.
GhostPenguin is a stealthy Linux backdoor that provides remote shell access and file-system operations over encrypted UDP, evading detection for months. It uses RC5 encryption and supports a wide range of attacker commands.
Multi-threaded Linux backdoor (C++) that collects host/network/system info, registers to C2, executes remote commands (including remote shell via /bin/sh), and performs file/directory operations; communicates with C2 over UDP port 53.
Linux backdoor malware, currently in early development, that provides unauthorized remote access to infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.