Setag, also known as BillGates or Ganiw, is a Linux malware family commonly characterized as a backdoor and historically associated with attacks against internet-facing servers. It has been observed in opportunistic exploitation campaigns that leverage recently disclosed server-side vulnerabilities to gain execution on unpatched systems. In one documented wave of exploitation, attackers used CVE-2021-26084 in Atlassian Confluence Server and Data Center to deploy Setag following unauthenticated remote code execution. Detection naming also places it in Unix-focused malware activity.
Setag is notable for combining persistent unauthorized access with botnet-style distributed denial-of-service functionality. Reported capabilities include multiple flood methods, specifically UDP, SYN, ICMP, and DNS flooding, indicating use in disruptive network attacks after compromise. Its operational profile aligns with post-exploitation use on compromised Linux servers, where it can serve as a foothold and attack node.
The malware has been described as targeting servers through one-day vulnerabilities, suggesting a deployment pattern centered on rapid weaponization of newly disclosed flaws rather than user-driven infection vectors. High-confidence reporting supports Linux and other Unix-like server environments as its primary platform. No additional capabilities beyond backdoor access and DDoS functionality are sufficiently established here at high confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In August 2021, Atlassian published a security advisory about CVE-2021-26084 that could enable a threat actor to run arbitrary code on unpatched Confluence Server and Data Center instances. After releasing the advisory, there occur massive scanning and proof-of-concept exploit code in public. We also collect a lot attacking traffic. | These threats include Cryptojacking, Setag backdoor, Fileless attack that uses PowerShell in a system to execute shell without file dropped and Muhstik botnet; we will elaborate each of them in this analysis.
ClamAV signatures include "Unix.Malware.Setag" in the list of malware activity associated with ongoing exploitation campaigns.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
An OGNL injection vulnerability exists that would allow an unauthenticated user to execute arbitrary code... numerous threat actors targeting this vulnerability whose goal was to download a malicious payload
The HandleSystools method of the CSystool class replaces the system tools /bin/netstat, /bin/lsof, /bin/ps, /usr/bin/netstat, /usr/bin/lsof, /usr/bin/ps, /usr/sbin/netstat, /usr/sbin/lsof and /usr/sbin/ps with copies of itself and backs up the original files
The C&C communication is encrypted in both directions with the same hard-coded XOR key (BB2FA36AAA9541F0) – which inspired the trojan’s name.
A bot running this type of execution is called as the /usr/bin/bsd-port/getty file.
The installation process can consist of several steps: • killing competing time-consuming processes
The HandleSystools method of the CSystool class replaces the system tools /bin/netstat, /bin/lsof, /bin/ps, /usr/bin/netstat, /usr/bin/lsof, /usr/bin/ps, /usr/sbin/netstat, /usr/sbin/lsof and /usr/sbin/ps with copies of itself and backs up the original files
Distributed DoS (DDoS) attacks are carried out using various methods such as volumetric flooding, slow HTTP attacks or TCP protocol misuse.
Observed types of attacks include volumetric SYN_Flood and DNS_Flood.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named Unix malware referenced via detection signatures as associated with Log4j exploitation campaigns; specific behavior not described in the provided content.
Malware family referenced via detection signatures as associated with Log4j exploitation activity; specific functionality not described in the content.
A well-known malware family targeting servers via 1-day vulnerabilities. It supports UDP/SYN/ICMP/DNS flood attacks for DDoS and also includes commands to check status and control compromised victims.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.