logo

GSocket Backdoor Delivered Through Bash Script, (Fri, Mar 20th)

ID: 0592b21e-b3a3-5a98-8e1b-42cecf2ee748

STIX ID: report--0592b21e-b3a3-5a98-8e1b-42cecf2ee748

Feed Name: SANS ISC Diary

Threat Score
70/100

Date Published: 2026-03-20

Date Updated: 2026-04-19

...
...

This report analyzes a malicious Bash script that deploys a GSocket (gs-netcat) backdoor, establishing outbound relay-based C2 communications and implementing cross-Unix persistence and anti-forensic timestamp restoration techniques. The analyst documents the installation paths, cron/profile persistence, embedded helper functions used to track and restore file timestamps, and provides IOCs including file SHA256 hashes and related references.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.