Threat actors targeted Huawei Cloud Elastic Cloud Service (ECS) instances with an upgraded Linux malware set designed for cryptojacking and broader cloud compromise. The operation deliberately interfered with Huawei Cloud defenses by disabling security-related services such as hostguard and abusing the cloudResetPwdUpdateAgent plugin, indicating environment-specific tradecraft rather than generic Linux opportunism. The attackers also sanitized infected systems by removing competing malware, deleting rival users and SSH keys, creating stealthy privileged accounts, installing Tor, and establishing persistence.
The campaign deployed two main payloads: an obfuscated ELF backdoor, linux64_shell, which used a CrossC2/Cobalt Strike-compatible library to communicate with command-and-control infrastructure, and a Go-based scanner, xlinux, built on the kunpeng framework to spread further. The scanner searched for weak credentials and exploitable services, including Oracle WebLogic systems vulnerable to CVE-2020-14882, underscoring how cloud misconfigurations and poor credential hygiene continued to provide a path for cryptojacking-focused intrusions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Trend Micro published research describing a malware campaign that deliberately targets Huawei Cloud Elastic Cloud Service instances for cryptojacking and cloud compromise. The report says the malware disables Huawei Cloud security components, abuses the cloudResetPwdUpdateAgent plugin, deploys a CrossC2-compatible backdoor and a Go-based scanner, and exploits weak credentials and CVE-2020-14882.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.