Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The HTTP server is equipped with a reverse connect backdoor that can be triggered via a special HTTP GET request. It is invoked when a request to a special path is performed with a query string in a particular format, containing the hostname and port to connect.
My instinct was right and I found out a new variant of Linux/CDorked.A... It could be either a kernel rootkit (Crowdstrike’s analysis of such rootkit here), an Apache module, or something else... Voilá, __syslog_chk was hooked and redirect into libkeysutils.so.1.3 library. This is an upgraded sshd rootkit version.
In the Linux/Cdorked binary all the important or suspicious strings are encrypted... decrypting the strings on demand with a static XOR key.
Three foreign binaries are installed in the filesystem, all three ending in space to hide in plain sight: '/usr/bin/s2p ', the trojaned httpd. '/usr/sbin/arpd ', the original httpd. '/usr/sbin/tunelp ', touch2 to restore time of original apache.
The HTTP request does not appear in Apache's log file due to the way the malicious code is hooked into Apache.
The original binary has been deleted! Definitely a good clue to understand why the httpd binary checksums are always ok... starts it again, and replaces again the trojaned binary with the original copy.
'/usr/sbin/tunelp ', touch2 to restore time of original apache... 182019 cmdline:touch-r/usr/sbin/arpd /usr/local/apache/bin/httpd
The HTTP server is equipped with a reverse connect backdoor that can be triggered via a special HTTP GET request. It is invoked when a request to a special path is done with a query string in a particular format
Now I could see a strange incoming SSH connection executing commands and after that the trojaned Apache was running... An incoming sshd connection stops the original Apache, copies over the trojaned version, starts it again, and replaces again the trojaned binary with the original copy.
Running the ipcs command revealed a very suspicious shared memory segment... slightly bigger than the one mentioned in those articles and detection tools.
The configuration is pushed by the attacker through obfuscated HTTP requests that aren't logged in normal Apache logs.
The configuration is pushed by the attacker through obfuscated HTTP requests that aren’t logged in normal Apache logs.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sophisticated Linux Apache backdoor that trojanizes httpd to filter and redirect web requests, uses shared memory, and in this variant swaps a malicious Apache binary in and out to hide filesystem evidence.
A sophisticated malicious replacement of the Apache httpd binary that injects malicious redirects on selected requests and provides a hidden reverse-connect backdoor. It stores configuration in shared memory and uses obfuscated HTTP requests to receive attacker commands while avoiding normal Apache logs.
A sophisticated Apache webserver backdoor that modifies the httpd binary, stores configuration in shared memory instead of disk, accepts covert HTTP-triggered commands, can open a reverse connect shell, and redirects visitors to malicious websites and exploit infrastructure while avoiding administrator detection and normal logging.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.