logo

Hiding Payloads in Linux Extended File Attributes, (Thu, Jul 17th)

ID: e2e6fe84-4984-53af-ad41-a977ea2ba7f0

STIX ID: report--e2e6fe84-4984-53af-ad41-a977ea2ba7f0

Feed Name: SANS ISC Diary

Date Published: 2025-07-17

Date Updated: 2026-04-19

...
...

This report illustrates a proof-of-concept for hiding a Python reverse-shell payload in Linux extended file attributes (xattr), splitting it across multiple files, obfuscating with XOR and Base64, and later reconstructing it with a C tool; it concludes with a simple defensive tip to hunt such misuse by recursively listing xattrs using `getfattr -R`.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.