Palo Alto Networks detailed Fysbis, a Linux trojan/backdoor attributed to the Sofacy group (APT28/Sednit), describing multiple samples spanning late 2014 through late 2015. The malware was found in both 32-bit and 64-bit ELF variants and could install either with or without root privileges, giving operators flexibility across different Linux environments. Researchers said the backdoor was modular, maintained persistence, and exposed its installation paths, capabilities, and configuration through relatively straightforward static analysis.
The newest observed variant showed incremental changes rather than a major redesign, including added obfuscation and use of the command-and-control domain mozilla-plugins[.]com, while retaining strong code and behavioral overlap with earlier samples tied to known Sofacy infrastructure. The reporting indicates that Fysbis was not especially sophisticated but remained operationally effective for cyber-espionage activity, underscoring that Linux systems continue to be viable targets where limited defensive visibility can raise enterprise risk.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
In late 2015, Sofacy used a newer 64-bit non-stripped Fysbis sample that retained similarities to earlier variants but added obfuscation and used mozilla-plugins[.]com as its command-and-control domain. The domain was described as previously unknown and potentially indicative of a newer Sofacy campaign.
In early 2015, Sofacy used a 32-bit stripped ELF Fysbis sample. It installed as /bin/ksysdefd or ~/.config/ksysdef/ksysdefd and beaconed to 198.105.125[.]74 over TCP port 80.
A 64-bit stripped ELF variant of the Fysbis Linux backdoor was used by Sofacy in late 2014. The sample installed as /bin/rsyncd with root or ~/.config/dbus-notifier/dbus-inotifier without root and communicated with azureon-line[.]com over TCP port 80.
Palo Alto Networks publicly analyzed three Fysbis Linux backdoor samples spanning late 2014 through late 2015, linking them to Sofacy infrastructure and documenting the malware's installation, persistence, and command-and-control behavior. The report assessed Fysbis as low in sophistication but operationally effective.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.