logo

DinodasRAT malware targets Linux servers in espionage campaign

ID: 273eefa1-d702-5096-bb50-f49939382bdb

STIX ID: report--273eefa1-d702-5096-bb50-f49939382bdb

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-03-31

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Kaspersky and other vendors have identified a Linux variant of the DinodasRAT (XDealer) targeting Red Hat and Ubuntu servers in an espionage campaign; the backdoor persists via SystemV/SystemD, uses TEA-encrypted TCP/UDP C2, provides full remote control and data exfiltration, and has been linked to an APT activity cluster (Earth Krahang/Operation Jacana) with victims across several countries since 2022/Oct 2023.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.