Auto-Color: An Emerging and Evasive Linux Backdoor
ID: 3cb8478c-4fee-593d-ba3d-553e765e1c5b
STIX ID: report--3cb8478c-4fee-593d-ba3d-553e765e1c5b
Feed Name: Palo Alto Networks Unit 42
Auto-color is a newly discovered Linux backdoor analyzed by Unit 42 that achieves persistence by installing a malicious ld.preload library implant and evades detection by hooking libc functions to hide network connections (modifying /proc/net/tcp). The malware uses a proprietary stream-like encryption for embedded C2 configuration, implements a custom encrypted C2 protocol with commands for reverse shells, file operations and proxying, and includes multiple compiled samples and C2 IPs targeting universities and government offices; the report provides detailed IoCs (SHA256 hashes, file names, and IP:port indicators) to aid detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
