Researchers reported continued use of the Rekoobe Linux backdoor in intrusions tied to China-linked APT31, including attacks against Korean organizations and Linux servers. Rekoobe, derived from the open-source Tiny SHell project, has appeared in multiple variants across x86, x64, and SPARC systems and typically provides file upload, file download, and reverse shell access. In one analyzed case, the malware contacted resolv.ctmailer[.]net:80, disguised its process name as /bin/bash, and protected command-and-control traffic with AES-128 encryption derived from an HMAC-SHA1 routine and a hard-coded password.
Separate analysis found Rekoobe operating alongside the Syslogk Linux kernel rootkit, forming a stealthy persistence and remote access toolkit. Syslogk, based on the open-source Adore-Ng rootkit, hides files, processes, and network activity, removes itself from kernel module listings, and can remotely start or stop Rekoobe using specially crafted TCP magic packets. Researchers also observed Rekoobe masquerading as a fake SMTP service and spawning a shell after receiving a specific backdoor command over TLS, reinforcing that the malware remains an active and adaptable threat to poorly maintained or unpatched Linux environments.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
ASEC published analysis of Rekoobe use against Korean organizations, linking the Linux backdoor to APT31 and describing multiple Korean-targeting samples and command-and-control endpoints. The report said ASEC had received Rekoobe malware reports from tenants in Korea for several years and assessed that poorly maintained or unpatched Linux servers were likely targets.
Avast disclosed technical analysis of Syslogk, a rootkit based on Adore-Ng, and the associated Rekoobe backdoor hidden at /etc/rc-Zobk0jpi/PgSD93ql. The report detailed how Syslogk concealed files, processes, and network activity and remotely started or stopped Rekoobe using crafted TCP packets.
Researchers found the Syslogk Linux kernel rootkit and its paired Rekoobe payload in the wild in early 2022. The analysis concluded the rootkit and backdoor were likely designed to operate together as a stealthy persistence and remote access toolkit.
ASEC reported that an updated version of Rekoobe was used in attacks in 2018, indicating continued development and operational use of the Linux backdoor.
Dr.Web published a malware description entry for Linux.Rekoobe.1, marking an early public documentation point for the Rekoobe Linux backdoor family.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 85 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
sansec.io
Open sourceasec.ahnlab.com
Open sourcedecoded.avast.io
Open sourcevms.drweb.com
Open sourceblog.sekoia.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.