Researchers identified Mokes, a cross-platform desktop backdoor family with Linux and Windows variants, later also linked to an OS X sample. The malware was designed for surveillance and data theft, supporting screenshots, keylogging, audio capture, and exfiltration of collected information. The Linux sample, detected as Backdoor.Linux.Mokes.a, was described as a UPX-packed C++/Qt implant statically linked with Qt, xkbcommon, and OpenSSL 1.0.2c, while the Windows samples were tracked as Backdoor.Win32.Mokes.imv and Backdoor.Win32.Mokes.imw.
Both variants used similar persistence and command-and-control logic, indicating a shared code base and operator playbook. On Linux, Mokes established autostart persistence; on Windows, it used Run registry keys and added active keylogging, with code also present for webcam capture. The malware beaconed every minute to hardcoded HTTP command-and-control servers and used TCP port 433 with a custom encrypted protocol for commands and data transfer. Researchers also noted that one Windows sample was signed with a trusted certificate chaining to COMODO RSA Code Signing CA, a tactic that could help the malware appear legitimate and evade scrutiny.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Kaspersky researchers analyzed Backdoor.OSX.Mokes.a, detailing its surveillance and theft capabilities, persistence via LaunchAgents, and encrypted command-and-control workflow. The report also published indicators of compromise including hashes, domains, an IP address, file paths, and a hardcoded User-Agent.
Analysis of the Linux Mokes sample found Qt installation timestamps indicating the malware was compiled no earlier than late September 2015 on Ubuntu 14.04 LTS.
A later Windows sample, detected as Backdoor.Win32.Mokes.imw, was reported as the first observed Mokes variant with its audio capture module activated, creating a new audio file every five minutes.
Researchers identified Mokes as a new desktop backdoor family spanning Linux and Windows, with surveillance and data exfiltration capabilities. The report also noted that an OS X variant was subsequently found.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.