XZ backdoor story – Initial analysis
ID: 2e8b029c-b12e-5858-a1f1-5fb35d0dbfd4
STIX ID: report--2e8b029c-b12e-5858-a1f1-5fb35d0dbfd4
Feed Name: Securelist by Kaspersky
A sophisticated multi-stage supply‑chain backdoor was introduced into XZ Utils (liblzma), shipped in releases 5.6.0/5.6.1 and distributed via some Linux vendor builds; the attack used hidden test files and a malicious build script to inject an object file that alters symbol resolution and hooks OpenSSL/OpenSSH internals (via IFUNC/GOT/symbind) to target sshd, enabling stealthy remote compromise. The analysis details the implantation chain, binary behavior, hooking mechanisms, execution checks, and provides hashes and YARA rules for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
