BridgeAgent is a Linux backdoor associated with the China-nexus Fire Ant espionage activity, which has been assessed to overlap with UNC3886 activity. It masquerades as a legitimate Zabbix monitoring agent and establishes root-level persistence through a systemd service. BridgeAgent communicates with attacker-controlled infrastructure over TLS and supports remote command execution, deployment of additional payloads, and TLS-enabled reverse shells. It was deployed on Linux management or staging hosts connected to compromised network infrastructure, enabling durable remote access and post-compromise operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Еще одной находкой исследователей стал Linux-бэкдор BridgeAgent, замаскированный под агент мониторинга Zabbix.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
TacTap... wrote collected credential material to an obfuscated log artifact... /var/log/.tacplus.acct [was an] XOR-obfuscated TACACS credential artifact.
BridgeAgent... polled the attacker's infrastructure over TLS on port 443 for commands and reverse-shell instructions.
Бэкдор BridgeAgent ... поддерживал ... загрузку дополнительных пейлоадов.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux backdoor disguised as a Zabbix monitoring agent. It establishes root-level systemd persistence, masquerades its process as /usr/bin/gnome-shell, communicates over TLS on port 443, and supports command execution, payload download, and reverse shells.
Linux backdoor masquerading as a monitoring agent. It stores encrypted configuration in /opt/.ICEauthority, communicates with external infrastructure over TLS, and serves as a staging point for scanning and access through the covert GRE tunnel.
A previously undocumented Linux backdoor masquerading as a Zabbix monitoring agent. It persists through a root-level systemd service, provides TLS reverse-shell access, and can execute additional payloads on compromised hosts.
Linux backdoor masquerading as a Zabbix monitoring agent. It persists through a root-level systemd service, disguises its process as gnome-shell, and polls C2 infrastructure over TLS/443 for commands and reverse-shell instructions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.