DinodasRAT Linux implant targeting entities worldwide
ID: d37ae0e1-0091-5414-951b-3801c2eb1d1b
STIX ID: report--d37ae0e1-0091-5414-951b-3801c2eb1d1b
Feed Name: Securelist by Kaspersky
**Executive Summary:** This report analyzes a previously undocumented Linux variant of DinodasRAT (V10), a cross-platform C++ backdoor used for espionage that targets Red Hat and Ubuntu systems, establishes persistence via SystemD/SysV scripts, generates a hardware-based UID, communicates with hard-coded C2 servers over TCP/UDP using TEA/CBC encryption, and exposes a wide range of remote-control and file-transfer capabilities; Kaspersky telemetry links the implant to campaigns affecting China, Taiwan, Turkey and Uzbekistan and detects it as HEUR:Backdoor.Linux.Dinodas.a.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
