logo

APT41’s New “Zero-Detection” Backdoor Targets Linux Workloads

ID: 8e3e9e4b-80d4-5313-8378-9494704c2d54

STIX ID: report--8e3e9e4b-80d4-5313-8378-9494704c2d54

Feed Name: securityonline.info

Threat Score
86/100

Date Published: 2026-04-15

Date Updated: 2026-04-23

Author: Ddos

...
...

Breakglass Intelligence reports a zero-detection ELF backdoor attributed to APT41 targeting Linux cloud workloads across AWS, GCP, Azure and Alibaba Cloud. The implant uses SMTP (port 25) as a covert C2 channel to exfiltrate cloud credentials and metadata, implements a selective C2 handshake to hide servers from scanners, and is supported by typosquatted domains and a multi-year Winnti Linux lineage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.