Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
Malware
/
tsh
Malware
tsh
Also known as:
TINYSHELL
Indicators of Compromise
4
Domain
mx[.]zxopfds[.]com
Filename
ntpdate
Filename
ora_ppmond
Filename
udevds
MITRE ATT&CK TTPs
7
T1027
Obfuscated Files or Information
Defense Evasion
T1055
Process Injection
Defense Evasion
T1071.001
Web Protocols
Command And Control
T1082
System Information Discovery
Discovery
T1090
Proxy
Command And Control
T1105
Ingress Tool Transfer
Command And Control
T1566
Phishing
Initial Access
Source Articles
Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
Linux backdoors have been observed targeting telecom and network appliances in South Korea and Taiwan by impersonating legitimate email security tools such as SpamSniper and ShareTech to evade detection. The threat involves a new variant of BPFDoor and a previously undocumented Linux implant named AVERAT, both using process name spoofing and C2 over SMTP on port 25. The BPFDoor variants are linked to the Red Menshen threat group and use BPF-based magic packet triggering wrapped in HTTPS POST requests to bypass deep packet inspection. AVERAT is deployed via a dropper that decrypts payloads using the key 'ShareTech' and supports extensive post-compromise capabilities including shell access, file upload/download, and process manipulation.
hacker-news
·
5h ago