logo

Stealthy 'sedexp' Linux malware evaded detection for two years

ID: a7c05a46-7ef7-5218-a50e-484a88a6afde

STIX ID: report--a7c05a46-7ef7-5218-a50e-484a88a6afde

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-08-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Aon/Stroz Friedberg researchers detail 'sedexp', a stealthy Linux malware active since at least 2022 that achieves persistence by adding malicious udev rules (triggering on /dev/random), masks itself via memory manipulation and process naming, establishes reverse shells for remote access, and has been used to hide credit-card scraping on compromised web servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.