logo

Stealthy Linux 'Auto-color' Backdoor Paints US Institutions With Malware

ID: 0edf080a-14e1-58ca-b0ef-f1abf7afc902

STIX ID: report--0edf080a-14e1-58ca-b0ef-f1abf7afc902

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-02-26

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Palo Alto Networks Unit 42 identified a stealthy Linux backdoor dubbed "Auto-color" deployed in attacks targeting educational and public-sector organizations in North America and Asia; the backdoor uses variable benign file names, a root-only library implant to hide network activity (manipulating /proc/net/tcp), prevents uninstallation, and encrypts C2/configuration with proprietary algorithms, and Unit 42 published IoCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.