RedXOR is a Linux backdoor assessed to be linked to Chinese state-sponsored activity, based on victimology, operational tradecraft, and code similarities with malware associated with the Winnti ecosystem. It masquerades as a legitimate policy-management daemon and uses the Adore-ng Linux kernel-module rootkit to conceal its process. RedXOR establishes persistence through system initialization service entries and runs detached in the background. Its configuration, including command-and-control settings, is stored encrypted in the binary. The backdoor communicates over TCP using XOR-based data encoding and traffic formatted to resemble HTTP. It provides system reconnaissance, file-management, pseudo-terminal shell access, self-update and uninstall functions, rootkit installation, and network port-mapping functionality implemented using a modified Rinetd component. RedXOR targets Linux endpoints and servers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We named it RedXOR for its network data encoding scheme based on XOR. Based on victimology, as well as similar components and Tactics, Techniques, and Procedures (TTPs), we believe RedXOR was developed by high profile Chinese threat actors.
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
After installing the binary to the hidden folder, the malware sets up persistence via “init” scripts. The following files are created after executing the malware on boot: /usr/syno/etc/rc.d/S99po1kitd-update.sh /etc/init.d/po1kitd-update /etc/rc2.d/S99po1kitd-update
After installing the binary to the hidden folder, the malware sets up persistence via “init” scripts. The following files are created after executing the malware on boot: /usr/syno/etc/rc.d/S99po1kitd-update.sh /etc/init.d/po1kitd-update /etc/rc2.d/S99po1kitd-update
“LKM rootkits leverage different kernel features to hook kernel functions” and are used “to hide malicious activity by hooking execution flow.”
A 2.7 MB ELF binary with near-maximum entropy (7.997 bits per byte across ~832 KB of code). The obfuscation isn't packing -- it's a custom code virtualizer or instruction-level transformation that renders static analysis effectively impossible without dedicated devirtualization tooling.
The most operationally significant capability is the backdoor's access to cloud instance metadata at 169.254.169.254 . This is the link-local address that every major cloud provider uses to serve instance credentials, API tokens, and configuration data to running workloads.
The malware communicates with the C2 server over a TCP socket. The traffic is made to look like HTTP traffic.
Network tunneling is enabled by sending the command code 4001 to the malware.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The group uses a variety of TTPs including but not limited to LoTL tactics, phishing, ransomware, cryptocurrency mining, supply chain attacks, China Chopper, Gh0st RaT, PlugX, HighNoon, Derusbi, BioPass RAT, RedXOR, and ShadowPad.
Referenced as an earlier malware in the Winnti ELF lineage.
Mentioned as a Chinese-nexus malware family whose RC4-MD5-related routines show code similarities to the newer BPFdoor controller.
Linux backdoor masquerading as a polkit daemon. It installs persistence via init scripts, can hide via the Adore-ng LKM rootkit, communicates with C2 over TCP disguised as HTTP using XOR-based encoding, collects system information, supports file operations, executes shell commands via a pseudo-terminal, can update/uninstall itself, and provides port-mapping/network tunneling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.