Researchers linked the Linux backdoor Linodas to the China-nexus espionage activity publicly associated with Earth Krahang, expanding understanding of a campaign that has targeted government entities across at least 35 countries. Trend Micro reported that the group compromised public-facing servers and used spear-phishing, stolen email accounts, and trusted government infrastructure to pivot into other ministries and agencies, with foreign affairs organizations heavily affected. The operation relied on custom malware including XDealer/DinodasRAT and RESHELL, alongside tools such as Cobalt Strike, PlugX, ShadowPad, SoftEther VPN, Mimikatz, and credential theft against Exchange and other mail services to support long-term intelligence collection.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
Check Point reported the latest Linux DinodasRAT sample it analyzed, carrying the internal version string Linux_%s_%s_%u_V11, was first seen in November 2023.
During Operation Jacana, the attackers used a previously undocumented C++ backdoor that ESET named DinodasRAT, delivered via spearphishing emails themed around Guyanese public affairs.
ESET detected a targeted spearphishing-led cyberespionage intrusion in February 2023 against a governmental entity in Guyana and named it Operation Jacana.
Trend Micro reported that since 2023, Earth Krahang has shifted from using RESHELL to XDealer, also known as DinodasRAT, and has used both Windows and Linux variants.
Check Point reported a later Linux DinodasRAT sample with the internal version string Linux_%s_%s_%u_V10 was first seen in January 2023.
Trend Micro said the Earth Krahang intrusion set has targeted government entities worldwide since early 2022, focusing especially on Southeast Asia while also reaching Europe, the Americas, and Africa.
Check Point reported the earliest cited Linux DinodasRAT sample, tracked as Linodas, was first seen in the wild in July 2021 and carried the internal version string Linux_%s_%s_%u_V7.
Check Point analyzed Linodas as the Linux branch of DinodasRAT/XDealer and attributed its use to a Chinese-nexus espionage actor aligned with publicly reported Earth Krahang activity, noting Linux-specific development and a shared C2 with a Windows sample.
Trend Micro disclosed a long-running cyberespionage campaign it named Earth Krahang, linking it to about 70 confirmed victims across 23 countries and describing abuse of compromised government infrastructure and email accounts to target other governments.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 29 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
research.checkpoint.com
Open sourcetrendmicro.com
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.