logo

New Linux malware is controlled through emojis sent from Discord

ID: 411b3950-f6fc-5077-81e0-cb168796e7c5

STIX ID: report--411b3950-f6fc-5077-81e0-cb168796e7c5

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-06-15

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

A Volexity report describes DISGOMOJI, a Linux backdoor used in an espionage campaign targeting Indian government desktops (notably the BOSS Linux distribution). The malware is delivered via a UPX-packed ELF in phishing archives, displays a PDF lure while installing additional payloads (including a USB-theft shell script), exfiltrates system information and files, persists via cron/XDG autostart, and is controlled through a Discord emoji-based C2 (using the open-source discord-c2 project); Volexity links the campaign to a suspected Pakistan-based actor tracked as UTA0137.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.