Security researchers have uncovered a previously undocumented Linux backdoor named GhostPenguin, which employs advanced evasion techniques to remain undetected. GhostPenguin is a multi-threaded backdoor written in C++ that provides remote shell access and comprehensive file system operations over an RC5-encrypted UDP channel. The malware establishes communication through a structured session handshake and uses multiple threads for registration, heartbeat signaling, and reliable command delivery. Its discovery was made possible through AI-driven, automated threat hunting pipelines that analyzed zero-detection Linux samples from VirusTotal, highlighting the growing importance of artificial intelligence in uncovering sophisticated threats.
GhostPenguin remains under active development, as indicated by the presence of debug artifacts and unused functions within its codebase. The backdoor's stealthy nature and use of encrypted communication channels make it particularly challenging for traditional security tools to detect. Security vendors have responded by updating their detection capabilities, with specific indicators of compromise (IoCs) now available for threat hunting and defense. The emergence of GhostPenguin underscores the evolving landscape of Linux-targeted malware and the necessity for advanced detection and response strategies in enterprise environments.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Trend Micro publicly disclosed technical details on GhostPenguin, including its command set, RC5-encrypted UDP protocol, persistence behavior, and indicators of compromise such as hashes and C2 server addresses. The company also stated that Trend Vision One detects and blocks the malware and provided hunting guidance for defenders.
Trend Micro Research identified GhostPenguin, a previously unknown multi-threaded Linux backdoor written in C++, through an AI-driven automated threat hunting pipeline analyzing zero-detection VirusTotal samples. The malware provides remote shell access, file system operations, and covert RC5-encrypted UDP command-and-control traffic over port 53.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.