Do shoot the messenger: Telegram-controlled backdoor trojan targets Linux servers
ID: dafc975f-784d-5f25-b233-01d5002ee771
STIX ID: report--dafc975f-784d-5f25-b233-01d5002ee771
Feed Name: Dr.Web News
Threat Score
Doctor Web analysts uncovered Linux.BackDoor.TgRat.2, a Linux variant of the TgRat RAT delivered by a trojan dropper that targets specific hosts by checking a hostname hash and is controlled through a Telegram bot; it supports file exfiltration, screenshots, remote command execution, uses RSA encryption and bash-based script execution, and the report includes IOCs and detection/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
