logo

GhostPenguin Backdoor With Zero-Detection Attacking Linux Servers Uncovered Using AI-Automated Tools

ID: d743ac3a-73ae-59c3-8aa8-26f5eb7273b2

STIX ID: report--d743ac3a-73ae-59c3-8aa8-26f5eb7273b2

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-09

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

GhostPenguin is a newly identified, multi-threaded C++ Linux backdoor that evaded detection for months by using a multi-stage architecture and RC5-encrypted UDP communications over port 53. The malware establishes a remote shell and extensive file-system manipulation capabilities, performs a handshake to obtain a 16-byte session ID used as the RC5 key, stores a PID file in the user's home directory to prevent duplicate instances, maintains a heartbeat every 500 ms, segments transfers to accommodate UDP limits, and supports roughly 40 commands; its design and minimal, encrypted traffic make detection difficult and resulted in zero VirusTotal detections for an extended period.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.