Stealthy Linux 'Auto-color' Backdoor Paints US Institutions With Malware
ID: 0edf080a-14e1-58ca-b0ef-f1abf7afc902
STIX ID: report--0edf080a-14e1-58ca-b0ef-f1abf7afc902
Feed Name: Dark Reading
Date Published: 2025-02-26
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Palo Alto Networks Unit 42 identified a stealthy Linux backdoor dubbed "Auto-color" deployed in attacks targeting educational and public-sector organizations in North America and Asia; the backdoor uses variable benign file names, a root-only library implant to hide network activity (manipulating /proc/net/tcp), prevents uninstallation, and encrypts C2/configuration with proprietary algorithms, and Unit 42 published IoCs and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
