New Linux Backdoor RedXOR Likely Operated by Chinese Nation-State Actor

Read the original article: New Linux Backdoor RedXOR Likely Operated by Chinese Nation-State Actor


We discovered a new sophisticated backdoor targeting Linux endpoints and servers Based on Tactics, Techniques, and Procedures (TTPs) the backdoor is believed to be developed by Chinese nation-state actors The backdoor masquerades itself as polkit daemon. We named it RedXOR for its network data encoding scheme based on XOR. The malware was compiled on Red Hat Enterprise […]

The post New Linux Backdoor RedXOR Likely Operated by Chinese Nation-State Actor appeared first on Intezer.


Read the original article: New Linux Backdoor RedXOR Likely Operated by Chinese Nation-State Actor