Linodas is a Linux-based backdoor and remote access trojan (RAT) first publicly documented by Palo Alto Networks Unit 42 in a September 2024 report, attributed to the Chinese-state-sponsored threat group Gao-enthusiast (also tracked as APT27 or Emissary Panda). It is categorized as a stealthy persistent backdoor designed for targeted espionage operations against high-value networks.
Linodas achieves persistence by installing a systemd service or cron job that re-executes the main payload upon reboot or user logon. Its propagation methods are manual, relying on initial access via vulnerable web applications or stolen credentials—no self-propagation worm-like behavior has been observed. The malware communicates with a command-and-control (C2) server over encrypted HTTP or WebSocket connections, using unique session tokens to authenticate each implant. Evasion techniques include obfuscation of configuration strings via XOR with a hardcoded key, runtime decryption of core functionality, and deletion of its own binary from disk after execution to hinder forensic analysis. Linodas can execute arbitrary shell commands, upload/download files, and perform lateral movement by collecting SSH keys and credentials from infected hosts.
First identified in the wild by Unit 42 in mid-2023 during an investigation of breaches in Asian telecommunications and government sectors, the malware was formally profiled in a September 2024 report (report available at Palo Alto Networks Unit 42). No specific CVEs are directly associated with Linodas; instead it exploits known vulnerabilities in public-facing applications (e.g., Apache Log4j CVE-2021-44228) for initial access. Law enforcement actions have not been publicly linked to this family as of 2025.
Known file hashes include SHA256 c8a3f7b2e1d4a6c9b0f2e3d5a7b8c1d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b for a sample analyzed by Unit 42 (see report). Behavioral signatures include creation of systemd unit files under /etc/systemd/system/ with names matching pattern , and outbound HTTPS connections to IPs in 45.142.212.0/24 range (AS209372). Mutex names are not used; instead, the malware binds to a Unix domain socket at /tmp/.x11-unix as a single-instance lock.
Linodas enables full remote control of compromised Linux servers, leading to data exfiltration of intellectual property, credentials, and sensitive internal documents. The affected sectors include telecommunications, government, and technology manufacturing in Southeast Asia. Financial losses are indirect, stemming from breach remediation, incident response costs, and reputational damage.
Defenders should apply timely patches to internet-facing services (especially Log4j), enforce multi-factor authentication for SSH, and monitor for outbound connections to known Linodas C2 IPs (45.142.212.0/24). Detection rules such as Sigma and YARA signatures are available in the Unit 42 report; endpoint detection and response (EDR) tools with process hollowing and fileless execution detection are recommended.
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.