ESET detailed Mumblehard, a malware family targeting Linux and BSD servers that installs a backdoor, a spam-sending daemon, and a general-purpose proxy on compromised systems. The malware’s components were largely Perl scripts encrypted and packed inside custom ELF binaries, and researchers said the operation was strongly linked to Yellsoft, a company known for bulk-email software marketed as DirectMailer. The backdoor contacted hardcoded command-and-control servers every 15 minutes over HTTP, pulled download-and-execute instructions hidden in Set-Cookie headers, and returned execution status through a crafted User-Agent string.
Researchers said the spam module communicated with its controllers using HTTP POST traffic over port 25 and supported configurable spam campaigns, with observed activity promoting pharmaceutical products. By sinkholing one backdoor domain, ESET recorded 8,867 unique IP addresses over seven months, with web servers making up most victims and infections appearing in intermittent waves. The report said likely infection vectors included exploitation of Joomla and WordPress sites, as well as trojanized pirated copies of Yellsoft’s DirectMailer that silently installed the Mumblehard backdoor and proxy components.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
ESET's sinkhole collection period ended on April 22, 2015. Over the observation window, the company recorded 8,867 unique IP addresses contacting the sinkhole, with an outage between December 7, 2014 and January 6, 2015.
ESET sinkholed one of the Mumblehard backdoor domains and began collecting telemetry from infected hosts. The collection period documented infected systems contacting the sinkhole and supported later victim-count analysis.
ESET reported that Mumblehard had been active since at least 2009, based on samples submitted to VirusTotal. This establishes the earliest known timeframe for the malware operation.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.