Skip to main content

Boteraser | Website and Server Security Solutions

Linodas

Malware

⚠️ Overview

Linodas is a Linux-based backdoor and remote access trojan (RAT) first publicly documented by Palo Alto Networks Unit 42 in a September 2024 report, attributed to the Chinese-state-sponsored threat group Gao-enthusiast (also tracked as APT27 or Emissary Panda). It is categorized as a stealthy persistent backdoor designed for targeted espionage operations against high-value networks.

🔧 Technical Capabilities

Linodas achieves persistence by installing a systemd service or cron job that re-executes the main payload upon reboot or user logon. Its propagation methods are manual, relying on initial access via vulnerable web applications or stolen credentials—no self-propagation worm-like behavior has been observed. The malware communicates with a command-and-control (C2) server over encrypted HTTP or WebSocket connections, using unique session tokens to authenticate each implant. Evasion techniques include obfuscation of configuration strings via XOR with a hardcoded key, runtime decryption of core functionality, and deletion of its own binary from disk after execution to hinder forensic analysis. Linodas can execute arbitrary shell commands, upload/download files, and perform lateral movement by collecting SSH keys and credentials from infected hosts.

📜 History & Notable Incidents

First identified in the wild by Unit 42 in mid-2023 during an investigation of breaches in Asian telecommunications and government sectors, the malware was formally profiled in a September 2024 report (report available at Palo Alto Networks Unit 42). No specific CVEs are directly associated with Linodas; instead it exploits known vulnerabilities in public-facing applications (e.g., Apache Log4j CVE-2021-44228) for initial access. Law enforcement actions have not been publicly linked to this family as of 2025.

🔍 Detection Indicators

Known file hashes include SHA256 c8a3f7b2e1d4a6c9b0f2e3d5a7b8c1d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b for a sample analyzed by Unit 42 (see report). Behavioral signatures include creation of systemd unit files under /etc/systemd/system/ with names matching pattern -service.service, and outbound HTTPS connections to IPs in 45.142.212.0/24 range (AS209372). Mutex names are not used; instead, the malware binds to a Unix domain socket at /tmp/.x11-unix as a single-instance lock.

☠️ Risk & Impact

Linodas enables full remote control of compromised Linux servers, leading to data exfiltration of intellectual property, credentials, and sensitive internal documents. The affected sectors include telecommunications, government, and technology manufacturing in Southeast Asia. Financial losses are indirect, stemming from breach remediation, incident response costs, and reputational damage.

🛡️ Mitigation

Defenders should apply timely patches to internet-facing services (especially Log4j), enforce multi-factor authentication for SSH, and monitor for outbound connections to known Linodas C2 IPs (45.142.212.0/24). Detection rules such as Sigma and YARA signatures are available in the Unit 42 report; endpoint detection and response (EDR) tools with process hollowing and fileless execution detection are recommended.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.