logo

Linux Malware DISGOMOJI Targets Indian Officials

ID: f557c037-f42e-541c-9da2-cd183da8837e

STIX ID: report--f557c037-f42e-541c-9da2-cd183da8837e

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2024-06-17

Date Updated: 2026-04-22

Author: do son

...
...

Volexity reports a targeted cyber-espionage campaign (attributed to UTA0137) against Indian government entities running the BOSS Linux distribution, deploying a Golang ELF loader that installs DISGOMOJI — a Linux backdoor that uses Discord channels and emojis for C2, supports file exfiltration, persistence via cron, USB harvesting, and employs DirtyPipe for privilege escalation; the report includes TTPs, IoCs and YARA rules to aid detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.