logo

Do shoot the messenger: Telegram-controlled backdoor trojan targets Linux servers

ID: dafc975f-784d-5f25-b233-01d5002ee771

STIX ID: report--dafc975f-784d-5f25-b233-01d5002ee771

Feed Name: Dr.Web News

Threat Score
65/100

Date Published: 2024-07-04

Date Updated: 2026-04-27

...
...

Doctor Web analysts uncovered Linux.BackDoor.TgRat.2, a Linux variant of the TgRat RAT delivered by a trojan dropper that targets specific hosts by checking a hostname hash and is controlled through a Telegram bot; it supports file exfiltration, screenshots, remote command execution, uses RSA encryption and bash-based script execution, and the report includes IOCs and detection/mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.