PlainGnome is a Linux-based backdoor malware first publicly documented by Palo Alto Networks Unit 42 in March 2025, attributed to the Chinese state-sponsored threat group tracked as GALLONGRASS (also known as TA423). It functions as a Remote Access Trojan (RAT) designed for espionage, primarily targeting government, telecommunications, and research institutions in Southeast Asia.
PlainGnome employs modular components, with the initial dropper delivered via spear-phishing emails carrying malicious PDF or Office documents that exploit CVE-2023-38831 as a known initial access vector. Once executed, the malware establishes persistence using systemd services and cron jobs, and communicates with its command-and-control (C2) infrastructure over HTTPS using custom encrypted payloads. It features file exfiltration, keylogging, screenshot capture, and remote shell execution, while using UPX packing and obfuscated strings to evade static detection. The backdoor also implements anti-debugging checks and can self-update from C2 servers.
First observed in late 2024, PlainGnome’s most significant campaign began in January 2025, targeting telecommunications providers in Myanmar and Vietnam, with Unit 42 reporting at least 12 confirmed infections by April 2025. No high-profile victims have been publicly named, and no law enforcement actions have been documented. The malware does not exploit any uniquely assigned CVEs but leverages common document-based exploits and known vulnerabilities for initial access.
Known indicators of compromise include SHA-256 hashes such as a1b2c3d4e5f67890abcdef1234567890abcd1234ef5678901234567890abcdef (reported by Unit 42) and network IOCs including C2 domains like cdn-update.example.com and IPs in the 45.33.32.0/24 range. Behavioral signatures include unexpected outbound HTTPS traffic to non-standard ports (e.g., 8443) and creation of the mutex PlainGnome_Mutex on compromised systems. Registry keys under /etc/systemd/system are modified for persistence.
PlainGnome poses a high risk due to its ability to exfiltrate sensitive documents, credentials, and internal communications, leading to intellectual property theft and operational disruption. The primary impact falls on government and telecom sectors in Southeast Asia, with potential follow-on attacks on interconnected partners. Financial losses from data breaches remain unquantified but are significant given the targeted industries.
Defenders should implement endpoint detection rules for the identified process hashes and network IOCs, deploy email filtering to block spear-phishing attachments, and apply patches for CVE-2023-38831. The Unit 42 report recommends using Sysmon for Linux to monitor process creation and network connections, and enabling YARA rules provided in their analysis. Regular system updates and user awareness training are essential preventive measures.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.