logo

Linux Version of DinodasRAT Spotted in Cyber Attacks Across Several Countries

ID: 2e91e42a-c09c-5edb-a3a0-d779b4720f0b

STIX ID: report--2e91e42a-c09c-5edb-a3a0-d779b4720f0b

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-03-28

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

DinodasRAT (also called XDealer or Linodas) is a C++ backdoor with a newly documented Linux variant used in targeted espionage against government and regional targets (China, Taiwan, Turkey, Uzbekistan, and previously Guyana). Analyses from Kaspersky and Check Point detail persistent SystemV/SystemD startup, TEA-encrypted C2 over TCP/UDP, file/process/shell command capabilities, modular functionality (including a filter module that proxies/controls binary output), evasion of debugging/monitoring tools, and attribution to China-nexus actors such as LuoYu and clusters like Earth Krahang.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.