Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
自从Log4J漏洞被曝光后... 2022年2月9日,360Netlab的蜜罐系统捕获了一个未知的ELF文件通过Log4J漏洞传播... B1txor20...目前通过Log4j漏洞传播 | 经过分析,我们确定是一个全新的僵尸网络家族,基于其传播时使用的文件名"b1t",XOR加密算法,以及RC4算法秘钥长度为20字节,它被我们命名为 B1txor20 。简单来说,B1txor20是一个针对Linux平台的后门木马, 它利用DNS Tunnel技术构建C2通信信道,除了传统的后门功能,B1txor20还有开启Socket5代理,远程下载安装Rootkit,反弹Shell等功能
14 distinct techniques documented for this family, organized by ATT&CK tactic.
98 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
GNU/Linux backdoor discovered in 2022 that exploited Log4Shell for intrusion and used DNS tunneling as its C2 channel.
Linux backdoor targeting ARM and x64 systems, first captured propagating through the Log4J vulnerability. It uses DNS tunneling for command-and-control, protecting messages with ZLIB compression, RC4 encryption, and custom Base64 encoding. Capabilities include arbitrary command execution, reverse shells, file reading and writing, sensitive-information uploads, SOCKS5 proxying, traffic forwarding, and remote rootkit installation. Some implemented functions are unused or defective.
Linux backdoor/botnet malware that spreads via the Log4j vulnerability and uses DNS tunneling for covert C2. It supports command execution, SOCKS5/proxy capability, traffic forwarding, reverse shell, file read/write, system info upload, and remote installation of a rootkit.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.