Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Another guess is the nature of abd program, by the argument -i passed from the parent, the environment setup, and the duplication of I/O on the socket file descriptor... We think that this executable can be a simple bash specifically packed.
One of the key characteristic of this malware is that it can be used both as a library that overrides well known APIs and also as an executable.
A backdoor was placed in our case in a running HTTPD, using a library injection... it can also be used as an executable to install itself by altering the imports of a library and copying itself. This way it stays resilient after an update.
On the compromised server, we found a modified httpd binary that imports a suspicious library m.so.6 before importing anything else... it forces the binary to imports this suspicious library first, to make sure its exported APIs override the ones provided by the system libraries.
The library exports the accept function. Overriding could allow the malware to hijack all inbound connections to the server.
When executed, it infects a given binary passed as first argument. But before doing anything, it actually duplicates its command line arguments in memory and wipes the original values with null bytes, this is a rare process tampering to evade forensic investigations.
Finally the malware tampers timestamps of the shortest library with the second argument times (again a forensics prevention).
A backdoor was placed in our case in a running HTTPD, using a library injection... it can also be used as an executable to install itself by altering the imports of a library and copying itself. This way it stays resilient after an update.
On the compromised server, we found a modified httpd binary that imports a suspicious library m.so.6 before importing anything else... it forces the binary to imports this suspicious library first, to make sure its exported APIs override the ones provided by the system libraries.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.