Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
AlphaAgent [is] a modular backdoor written in Go, built to land quietly, blend into a busy host, take orders over an encrypted channel, and hand its operator everything they need to work through a network.
AlphaAgent [is] a modular backdoor written in Go, built to land quietly, blend into a busy host, take orders over an encrypted channel, and hand its operator everything they need to work through a network.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
AlphaAgent can install an embedded rootkit kernel module; other builds carry a component that hides processes and network connections at kernel level.
Most tools are wrapped in packing and virtualization layers; one AlphaAgent variant unpacks only in memory, obfuscates internals, and exits when a debugger is detected.
DownPro uses names such as systemd-udevd and rsync-tsl; oRAT installs as xtables-addons and impersonates sshd: root@pts/0.
AlphaAgent sets HISTFILE=/dev/null before executing remote shell commands.
AlphaAgent inventories active connections and interface addresses; info.sh gathers listening TCP ports and ARP neighbors.
AlphaAgent primarily uses gRPC over HTTPS; oRAT multiplexes HTTP requests over TCP, TLS/TCP, or QUIC/UDP sessions.
An AlphaAgent variant encrypts and Base32-encodes jobs, splits them across DNS labels, and exchanges them as TXT-style traffic on port 53.
AlphaAgent bundles a SOCKS5 proxy, yamux multiplexer, Ligolo-style relay, and a relay listener that forwards traffic upstream.
AlphaAgent supplies web-terminal, file transfer, proxying, and relay features; oRAT supports remote command execution, file transfer, SOCKS proxying, and embedded SSH/SFTP.
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux backdoor supporting remote command execution, file transfer, tunneling, and host discovery. A newer build included an AI-plugin execution path, though its function was not established from the sample.
Modular backdoor deployed by Gambling Goblin on compromised servers.
A modular Go Linux backdoor supporting encrypted gRPC/HTTPS, DNS, or HTTP C2; remote shell and PTY access; file transfers; host and SSH-key collection; SOCKS/Ligolo-style tunneling; relay operation; persistence; process masquerading; and optional procfs or kernel-level hiding.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.