ELF_PLEAD is a Linux backdoor associated with the BlackTech espionage group. It is the Linux counterpart to the Windows PLEAD malware and shares substantial code, command structure, processing flow, and encryption-related logic with that family. BlackTech has used ELF_PLEAD alongside other malware families such as TSCookie and KIVARS in operations targeting both Linux and Windows environments.
ELF_PLEAD stores an encrypted configuration containing command-and-control server information and encryption material. The configuration is RC4-encrypted, and the malware derives communication keys through an initial key-exchange process before using the resulting RC4 key for subsequent traffic. Its network communications use a custom protocol rather than HTTP, and transmitted data is encrypted and compressed.
The malware provides a broad remote-access feature set oriented toward post-compromise control. Supported functions include file and directory listing and manipulation, file upload and download, execution of files, remote shell access, and port-forwarding or proxy capabilities. It also supports malware-control operations such as reconnecting, restarting, terminating execution, changing sockets, and switching command-and-control servers. These capabilities make ELF_PLEAD a flexible Linux intrusion tool suited to long-term espionage operations and remote administration of compromised hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
The functions visible in Figure 1 hint that the binary makes a connection to some infrastructure using SSL... The backdoor connects to an IP (168.95[.]1.1)... The backdoor described in the November 2020 post utilized the domain mx[.]msdtc.tw for command and control.
The command and command numbers that differ from the prior sample are listed below: 11C SockClient >> Client/Server proxy mode 11C TravClient
CFileTransfer (group number 1): commands for sending/receiving files ... 70 Download file ... 75 Upload file
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another example of evolving Linux malware.
Named as a BlackTech-associated backdoor in related content only; no operational details are provided in the article itself.
Linux variant of the PLEAD malware used by BlackTech. It stores RC4-encrypted configuration containing C2 servers and keys, uses a custom C2 protocol with RC4 encryption and LZO compression, and supports file operations, file transfer, remote shell, proxy/port forwarding, reconnect/restart, and C2 switching.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.