Analysis of a Low-Detection Linux Implant With Hands-On Intrusion Capabilities

Summary
Researchers analyzed a low-detection, statically linked Linux backdoor delivered as a PNG-named ELF. It profiles hosts, communicates with C2, executes commands, transfers files, and supports reverse tunnels; later analysis noted similarities to Adaptix Agent.
Key points
- The implant is a statically linked x86-64 Linux backdoor written in C++; it was delivered as gregbfdah.png from an AWS-hosted URL and had minimal VirusTotal detection.
- It decrypts an embedded AES-128-GCM configuration, uses MessagePack for configuration and C2 messages, and profiles the infected host for beacon registration.
- Supported commands include program execution, file access and transfer, process management, interactive PTY sessions, and reverse tunnels for pivoting.
- The analysis describes the implant as low-prevalence and potentially suited to hands-on, targeted network intrusions; this is an assessment, not confirmation of a specific intrusion.
- A later update reported similarities to Adaptix Agent and its adaptix_gopher protocol.
- Reported indicators: SHA-256 f264f04f597a2bdda372a27ae701c18d4036175b1eb8722db5f8531615b38788; C2 iot.981666[.]xyz:8080; delivery URL zapier-logos.s3.amazonaws[.]com/gregbfdah.png.
Article Details
- Attack Vectors
- An ELF implant was delivered from the specified AWS-hosted URL; the article does not establish how a victim was induced to execute it.
- When run with the -nodel argument, the implant daemonizes, profiles the host, and registers with a C2 server. Without that argument, it self-deletes.
- C2 commands support program execution, file reads and writes, file exfiltration, permission and timestamp changes, and reverse tunnels for pivoting.
- Defensive Notes
- Investigate the identified ELF hash, delivery URL, and C2 host in relevant host and network telemetry.
- The implant's host profiling, encrypted registration beacon, self-deletion behavior, and reverse-tunnel capability provide behaviors to investigate.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| HOSTNAME | iot[.]981666[.]xyz | C2 host listed with port 8080. |
| SHA256 | f264f04f597a2bdda372a27ae701c18d4036175b1eb8722db5f8531615b38788 | SHA-256 hash listed for the ELF implant. |
| URL | hxxps[:]//zapier-logos[.]s3[.]amazonaws[.]com/gregbfdah[.]png | Specific AWS-hosted URL identified as delivering the ELF implant. |
MITRE ATT&CK
T1005 · Data from Local SystemC2 commands can read small local files and prepare larger files for exfiltration.T1016 · System Network Configuration DiscoveryThe implant obtains a local IP address and enumerates network interfaces to find a MAC address for its host fingerprint.T1027 · Obfuscated Files or InformationThe implant's embedded configuration is encrypted with AES-128-GCM.T1041 · Exfiltration Over C2 ChannelThe implant supports chunked file exfiltration through a C2 command.T1057 · Process DiscoveryA C2 command lists processes, described as equivalent to ps aux.T1070.004 · File DeletionThe implant self-deletes if it is not executed with the -nodel argument.T1070.006 · TimestompA C2 command changes file access and modification times using utimensat.T1082 · System Information DiscoveryBefore C2 registration, the implant collects the hostname, OS details, process information, and root status.T1083 · File and Directory DiscoveryC2 commands can list directories and enumerate the root directory.T1090 · ProxyThe implant supports reverse port forwarding and bidirectional data relay through pivot tunnels.T1105 · Ingress Tool TransferA C2 command writes delivered files to disk and can unzip them.T1222.002 · Linux and Mac PermissionsA C2 command changes file permissions using chmod.T1573.001 · Symmetric CryptographyThe implant encrypts its registration beacon with a configured AES-128 key and decrypts subsequent C2 instructions with a generated session key.