Researchers disclosed a stealthy Linux backdoor, tracked as Linux/Cdorked.A, that replaced the Apache httpd binary on cPanel-hosted servers and intermittently injected malicious 302 redirects into web traffic. Victims were sent to fast-changing attacker-controlled domains that delivered malware, spam and adult-content redirects, and in many cases the Blackhole Exploit Kit using known Java and PDF exploits. Investigators linked the activity to a decline in earlier DarkLeech-style infections, suggesting the operators may have shifted from malicious Apache modules to a harder-to-detect binary replacement.
The malware was designed to evade administrators by storing configuration in shared memory, avoiding normal Apache logs, preserving file timestamps, and in some cases marking the trojanized binary immutable. Analysts said the campaign appeared to target Apache deployments installed through cPanel, not necessarily because cPanel itself was vulnerable, but because its Apache installation and logging model made compromise harder to spot. The initial root-level intrusion vector remained unconfirmed, with suspected paths including SSH brute-force attacks, phishing, or stolen credentials, while defenders were advised to use file-integrity monitoring, anti-malware scanning, and checks for artifacts such as the string open_tty in the Apache directory to identify tampered binaries.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
ESET clarified that Linux/Cdorked.A does leave a disk artifact: a modified Apache httpd binary, even though its operational data and payload reside in shared memory. The clarification also noted that rebooting removes the in-memory payload and that file-integrity monitoring or anti-malware scanning can detect the altered binary.
On April 26, 2013, public reporting described a shift from Darkleech-style malicious Apache modules to trojanized Apache httpd binaries on cPanel-based servers. The disclosures detailed stealth features, intermittent malicious redirects, and ESET's classification of the malware as Linux/Cdorked.A.
Cisco TRAC reported that it first observed the Linux/CDorked Apache backdoor on March 4, 2013. The emergence coincided with a decline in DarkLeech infections, suggesting a possible connection between the campaigns.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
welivesecurity.com
Open sourceblogs.cisco.com
Open sourcearstechnica.com
Open sourceblog.sucuri.net
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.