ZinFoq is a Linux ELF post-exploitation implant written in Go and commonly referred to as ZinFoq. Huntress reported it during active exploitation of CVE-2025-55182 (React2Shell) against vulnerable React Server Components / Next.js deployments in December 2025. It was recovered as a statically compiled Go binary, with one reported sample SHA256 0f0f9c339fcc267ec3d560c7168c56f607232cbeb158cb02a0818720a54e72ce, and is often dropped as /usr/bin/dockerd-update. Reported capabilities include command execution, interactive and reverse PTY shells, file browsing and exfiltration, file operations, SOCKS5 proxying for network pivoting, TCP port forwarding, timestomping, bash history clearing, and process-name masquerading. It communicates over HTTPS with api.qtss[.]cc using hex-encoded payloads and has been observed using the User-Agent string "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_8; en-us) AppleWebKit/534.50 (KHTML, like Gecko) Version/5.1 Safari/534.50" to masquerade as Safari on macOS. Additional reporting describes ZinFoq as a more destructive variant used for sabotage rather than espionage, deployed by a different actor cluster than EtherRAT. Anti-forensics and evasion behaviors attributed to ZinFoq include copying /bin/ls access, modify, and change timestamps onto itself, clearing bash history, disguising itself as legitimate Linux services, and monitoring /proc for analysis tools such as wireshark, tcpdump, strace, and sysdig; if detected, it reportedly self-destructs by wiping memory, deleting its on-disk binary, and exiting. It has been associated with Linux-focused intrusion activity affecting multiple sectors, including construction and entertainment, and YARA coverage has been published for ELF detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
We identified a Go-based post-exploitation implant we've dubbed ZinFoq, which features interactive reverse shells, SOCKS5 proxying for network pivoting, and timestomping capabilities for anti-forensics. | Huntress is seeing threat actors exploit a vulnerability in React Server Components (CVE-2025-55182) across several organizations... Dubbed “React2Shell”, CVE-2025-55182 exists due to insecure deserialization... and can be exploited by unauthenticated attackers merely by crafting one malicious HTTP request.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The commands follow the same methodology: download a shell script, execute it via bash, and in some cases delete the script to remove evidence.
The binary copies itself to /bin/systemd-daemon and enables the service using the generic "System Daemon" description.
PeerBlight overwrites argv[0] in memory to hide its original path ... and replaces it with [ksoftirqd].
Finally, the script removes the downloaded temporary file, deletes the dropper script itself, clears the bash command history, and truncates the “.bash_history” file to eliminate evidence of the infection chain.
The payload, which we have named “ ZinFoq ” ... communicates with command-and-control infrastructure at “ api.qtss[.]cc ” over HTTPS using hex-encoded payloads
All C2 traffic uses standard HTTP POST requests with a User-Agent string crafted to masquerade as Safari on macOS
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive Go-based Linux wiper/sabotage variant. Uses timestomping by copying /bin/ls timestamps to its own binary to evade time-based triage, and includes a defensive self-destruct routine that triggers on analysis/monitoring tools (e.g., wireshark, tcpdump, strace, sysdig) by wiping memory, deleting itself from disk, and terminating.
A Linux ELF implant identified via YARA by unique hardcoded strings; discussed as a distinct Linux threat/implant family.
Linux post-exploitation implant providing interactive shell, file and network operations, proxying, timestomping, and evasion by masquerading as system services.
Go-based post-exploitation implant that communicates over HTTPS with hex-encoded payloads, supports shell execution, file operations, exfiltration, reverse PTY shell, SOCKS5 proxying, port forwarding, timestomping, bash history wiping, and process masquerading.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.