DISGOMOJI is a Linux backdoor associated with the Pakistan-linked threat actor UTA0137. It uses Discord for command-and-control, translating emoji-based messages into operational commands. Supported functions include capturing screenshots, exfiltrating files, and terminating processes. DISGOMOJI establishes persistence through XDG Autostart Entries, placing malicious desktop-entry files in a user autostart location so its backdoor executes whenever the desktop user logs in. Its autostart entries may use legitimate-looking names and extensive comment padding to hinder inspection and forensic analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In one notable campaign, Pakistan-linked APT group UTA0137 used "Disgomoji" malware that translated simple emojis sent over Discord into operational commands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that uses emoji-based command-and-control over Discord, translating emojis into operational commands such as capturing screenshots, exfiltrating files, and terminating processes.
Linux malware that maintains persistence by dropping .desktop files such as GNOME_Core.desktop or GNOME_GNU.desktop into ~/.config/autostart so its executable runs automatically at each user login; it also pads files with large numbers of # characters to hinder analysis.
Malware referenced as using an XDG .desktop autostart entry in ~/.config/autostart/ to execute a planted backdoor at user desktop login.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.