Researchers linked multiple Linux intrusions to suspected Chinese state-sponsored activity using the open-source Reptile kernel rootkit and a custom implant known as Mélofée. ExaTrack reported that Mélofée targeted Linux servers with capabilities for file and directory operations, shell execution, persistence, and command-and-control over TCP, TLS, and UDP/KCP, while one 2022 sample embedded a kernel-mode rootkit derived from Reptile. The installer deployed components under the disguised path /etc/intel_audio/, loaded the malicious kernel module with insmod, and established persistence through startup files such as /etc/rc.modules, tying the activity to infrastructure and tooling associated with Winnti, ShadowPad, PlugX, Spark, HelloBot, StowAway, and Cobalt Strike.
AhnLab later documented a Korean intrusion that used Reptile in a nearly identical way, including installation under /etc/intel_audio/, manual kernel-module loading instead of the default loader flow, persistence via rc.local, and deployment alongside an ICMP backdoor called ISH. Reptile provides stealth features for files, directories, processes, file contents, and network traffic, and can activate a reverse shell through a Port Knocking mechanism using Magic Packets. The overlap in installation path and deployment method matched patterns previously highlighted by ExaTrack and reinforced assessments that Reptile-derived Linux rootkits were being operationalized in broader Chinese espionage campaigns, including activity Mandiant associated with exploitation of Fortinet zero-days and custom malware.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
AhnLab reported a Korean intrusion case in which Reptile was installed under /etc/intel_audio/ with hard-coded configuration values and persistence via rc.local. The attacker manually loaded the kernel module with insmod instead of using Reptile's standard loader flow, and AhnLab noted similarities to ExaTrack's Mélofée/Winnti-linked activity.
ExaTrack published research on the Mélofée Linux implant and attributed the activity with high confidence to the China-linked Winnti group. The report documented a modified Reptile rootkit installed under /etc/intel_audio/ and loaded directly with insmod.
AhnLab cited Mandiant as confirming that a China-based threat group used the Reptile rootkit in attacks exploiting a Fortinet zero-day vulnerability. This connected the open-source Linux rootkit to real-world espionage operations.
ExaTrack assessed a third Mélofée sample to date from late April or May 2022 and said the related tooling and infrastructure were used by Chinese state-sponsored attackers during at least all of 2022. The activity included deployment under /etc/intel_audio/ and loading a Reptile-derived rootkit with insmod.
ExaTrack identified another Mélofée sample labeled 20220308, showing continued development of the implant's communications, configuration handling, and functionality. The family included a modified Reptile-based rootkit in at least one sample.
ExaTrack reported that one of the three identified Mélofée samples was labeled 20220111, indicating an early 2022 stage of the Linux implant's development. The malware family was linked with high confidence to Chinese state-sponsored activity, particularly the Winnti cluster.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 69 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourceblog.exatrack.com
Open sourcemandiant.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.