Group-IB disclosed a previously undocumented Linux remote access trojan, Krasue, that has been active since at least 2021 and has primarily targeted organizations in Thailand, including telecommunications companies. The malware is designed to preserve long-term access on compromised Linux systems, using AES-CBC encrypted command-and-control communications and masking keepalive traffic as RTSP DESCRIBE requests to blend into normal network activity. Investigators said Krasue is likely deployed in later stages of intrusions, potentially by botnet operators or initial access brokers, and notifications were sent to ThaiCERT and TTC-CERT.
Krasue also carries an embedded Linux kernel-module rootkit built for multiple kernel versions, enabling it to hide files, processes, ports, and its own presence while resisting termination. Group-IB assessed with moderate confidence that the malware shares a rootkit author or source-code lineage with XorDdos, a long-observed Linux malware family previously documented by Microsoft as a stealthy threat targeting Linux devices. While attribution to a specific threat actor remains inconclusive, the overlap suggests Krasue may be part of a broader ecosystem of Linux-focused malware used to maintain covert persistence on enterprise systems.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft published a security blog analyzing XorDdos as a stealthy DDoS malware family targeting Linux devices. This prior public reporting provides context for Group-IB's later assessment of code or author overlap between Krasue and XorDdos.
Group-IB reported that the previously undocumented Linux remote access trojan Krasue has been active since at least 2021, based on samples first registered on VirusTotal that year. The malware predominantly targeted organizations in Thailand, including telecommunications companies.
Group-IB disclosed a previously undocumented Linux RAT named Krasue, detailing its AES-CBC-encrypted command-and-control, RTSP DESCRIBE keepalive camouflage, and embedded kernel rootkit. The company also said it had notified ThaiCERT and TTC-CERT and assessed with moderate confidence that Krasue shares a rootkit author or source-code lineage with XorDdos.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.