logo

DinodasRAT Linux implant targeting entities worldwide

ID: d37ae0e1-0091-5414-951b-3801c2eb1d1b

STIX ID: report--d37ae0e1-0091-5414-951b-3801c2eb1d1b

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2024-03-28

Date Updated: 2026-04-29

Author: Anderson Leite, Lisandro Ubiedo

...
...

**Executive Summary:** This report analyzes a previously undocumented Linux variant of DinodasRAT (V10), a cross-platform C++ backdoor used for espionage that targets Red Hat and Ubuntu systems, establishes persistence via SystemD/SysV scripts, generates a hardware-based UID, communicates with hard-coded C2 servers over TCP/UDP using TEA/CBC encryption, and exposes a wide range of remote-control and file-transfer capabilities; Kaspersky telemetry links the implant to campaigns affecting China, Taiwan, Turkey and Uzbekistan and detects it as HEUR:Backdoor.Linux.Dinodas.a.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.