logo

New Backdoor Auto-color Linux Targets Systems in US and Asia

ID: 7556c022-8f85-5a23-982a-3f3e5cca28e0

STIX ID: report--7556c022-8f85-5a23-982a-3f3e5cca28e0

Feed Name: HackRead

Threat Score
72/100

Date Published: 2025-02-27

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Palo Alto Networks Unit 42 discovered Auto-color, a sophisticated Linux backdoor active between November and December 2024 that targets education and government organizations in North America and Asia. The malware uses innocuous filenames with varying hashes (due to embedded encrypted C2 payloads), installs a malicious library (using ld.preload to override system functions when possible), hooks libc functions to hide network activity by altering /proc/net/tcp, and communicates with attackers via a custom stream cipher; Unit 42 recommends stricter privilege controls, behavioural detection, and continuous Linux monitoring to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.