Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Passive backdoors are also used by some of the most advanced attackers, such as... the famous Equation Group with their Bvp47 or DewDrop implant.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
we are dealing with a port knocking backdoor... Port knocking removes the need for port listening backdoors and hiding those listeners from traditional network tools... implemented as a custom sniffer looking for a magic packet (or a group of magic packets) and do something when it matches such as open a port, make a callback to a remote host
DEWDROP h : linux kernel privesc ... CVE-2003-0961 ... PTRACE/FORKPTY / km3 : linux kernel lpe ... CVE-2003-0127 ... EXACTCHANGE : NULL-deref based local-root ... ENVOYTOMATO LPE through bluetooth stack(?) ESTOPMOONLIT Linux LPE ... elatedmonkey : cpanel privesc (0day) ... endlessdonut : Apache fastcgi privesc
Strings are XOR obfuscated... All the library original strings are removed to avoid (easy) library identification... The data contents are encrypted with RC5/6
It redirects all output to /dev/null , removes all signal handlers... Core files are disabled
we are dealing with a port knocking backdoor... Port knocking removes the need for port listening backdoors and hiding those listeners from traditional network tools... implemented as a custom sniffer looking for a magic packet (or a group of magic packets) and do something when it matches such as open a port, make a callback to a remote host
a libpcap sniffer is installed... We just need to install a listener and activate a BPF based filter since we don’t need to capture everything... Locate the network interfaces to sniff at. Compile a filter. Install the filter. Start sniffing. Get matching packets into a callback.
a libpcap sniffer is installed... We just need to install a listener and activate a BPF based filter since we don’t need to capture everything... Locate the network interfaces to sniff at. Compile a filter. Install the filter. Start sniffing. Get matching packets into a callback.
we are dealing with a port knocking backdoor... Port knocking removes the need for port listening backdoors and hiding those listeners from traditional network tools... implemented as a custom sniffer looking for a magic packet (or a group of magic packets) and do something when it matches such as open a port, make a callback to a remote host
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Equation toolset implant noted for using BPF-based packet filtering.
A multi-platform port-knocking backdoor from the ShadowBrokers-leaked NSA toolset. It installs a libpcap-based sniffer, uses an embedded BPF program to detect specially crafted trigger packets, and upon a valid knock can execute a callback for covert remote access without exposing a listening port.
Referenced as another Equation toolset implant that used BPF-related packet filtering concepts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.