ESET disclosed Linux/Mumblehard, a Linux malware family that reportedly remained active for more than five years while turning compromised servers into spam relays. The malware was described as two Perl-based components—a backdoor and a spamming daemon—hidden behind a custom assembly-language packer designed to obfuscate the Perl source and hinder analysis. Researchers said the operation primarily targeted web servers and abused the trusted reputation of legitimate server IP addresses to improve spam delivery.
After sinkholing one command-and-control domain, ESET observed more than 8,500 unique IP addresses showing Mumblehard-related behavior, including over 3,000 affected machines during the first week of April alone. The company also reported strong links between the malware and Yellsoft, citing overlapping infrastructure and pirated copies of Yellsoft DirectMailer that silently installed the Mumblehard backdoor, suggesting the spam botnet spread in part through trojanized software used on Linux servers.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
ESET publicly revealed the Linux/Mumblehard malware family, describing its Perl-based backdoor and spamming daemon, sinkhole observations of more than 8,500 unique IPs, and evidence linking the operation to Yellsoft and pirated DirectMailer copies.
During the first week of April, ESET observed more than 3,000 machines affected by Linux/Mumblehard while monitoring the botnet through a sinkholed command-and-control domain.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.