Bvp47 is a highly stealthy Linux backdoor attributed to the Equation Group and assessed to have been used in long-running, highly targeted espionage operations. It is designed for covert remote control and uses asymmetric cryptography to protect command activation, with reporting indicating that operation of key functionality required possession of the operator’s private key. The malware has been linked to technical components associated with other Equation Group tooling, including DewDrop, and has been described as part of a broader Unix-oriented framework spanning mainstream Linux distributions and other Unix-like platforms.
Operational reporting describes Bvp47 as a passive or covertly activated implant used on Internet-facing Linux systems, particularly systems positioned as bridges between external infrastructure and internal networks. A notable feature is its covert channel based on specially crafted TCP SYN packets, enabling command-and-control without conventional noisy beaconing. In observed intrusions, the implant functioned as a relay node between an external operator-controlled system and compromised internal servers, facilitating command delivery, payload staging, and encrypted return of execution results.
Observed post-compromise activity associated with Bvp47 included use of SMB and PowerShell to access internal systems, perform administrator logons, enumerate directories, schedule tasks, execute scripts, and move additional payloads between hosts. The malware and its surrounding tradecraft also incorporated code obfuscation, system hiding, and a self-destruction capability intended to reduce forensic visibility and hinder detection. Reporting indicates it remained largely undetected for more than a decade despite use against a relatively small but strategically selected victim set.
Bvp47 has been associated with intrusions affecting telecommunications, military, higher education, economic, and scientific organizations across dozens of countries. Its limited apparent deployment, advanced covert communications, and integration into multi-stage intrusion workflows are consistent with a bespoke espionage backdoor reserved for high-value operations by a sophisticated state-linked actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A report released today dives deep into technical aspects of a Linux backdoor now tracked as Bvp47 that is linked to the Equation Group.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The Bvp47 sample obtained from the forensic investigation proved to be an advanced backdoor for Linux with a remote control function protected through the RSA asymmetric cryptography algorithm
the implant featuring an "advanced covert channel behavior based on TCP SYN packets, code obfuscation, system hiding, and self-destruction design."
the implant featuring an "advanced covert channel behavior based on TCP SYN packets, code obfuscation, system hiding, and self-destruction design."
the implant featuring an "advanced covert channel behavior based on TCP SYN packets, code obfuscation, system hiding, and self-destruction design."
including logging in to the [business] server with an administrator account
the implant featuring an "advanced covert channel behavior based on TCP SYN packets..."
A connection between the two internal machines is used to communicate encrypted data via “its own protocol,”
The business server then connected to the email machine to download additional files, “including the Powershell script and the encrypted data of the second stage.”
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Bvp47 is mentioned as an example in the context of rootkits/backdoors, but the content provides no operational detail beyond naming it.
A sophisticated passive backdoor/implant referenced as a comparison point for the analyzed malware.
A Linux backdoor attributed to the Equation Group that uses a covert TCP SYN-based channel, supports encrypted remote control, code obfuscation, stealth/hiding, and self-destruction. It appears to act as a control bridge on internet-facing systems and includes a loader that decodes and loads the payload into memory.
Advanced Linux backdoor with remote control functionality protected by RSA asymmetric cryptography. It was reportedly used in highly targeted intrusions, enabled multi-stage operations across internal servers, and supported covert encrypted communications and lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.