Analysis of a Low-Detection Linux Implant With Hands-On Intrusion Capabilities

· Original article ↗

Summary

Researchers analyzed a low-detection, statically linked Linux backdoor delivered as a PNG-named ELF. It profiles hosts, communicates with C2, executes commands, transfers files, and supports reverse tunnels; later analysis noted similarities to Adaptix Agent.

Key points

  • The implant is a statically linked x86-64 Linux backdoor written in C++; it was delivered as gregbfdah.png from an AWS-hosted URL and had minimal VirusTotal detection.
  • It decrypts an embedded AES-128-GCM configuration, uses MessagePack for configuration and C2 messages, and profiles the infected host for beacon registration.
  • Supported commands include program execution, file access and transfer, process management, interactive PTY sessions, and reverse tunnels for pivoting.
  • The analysis describes the implant as low-prevalence and potentially suited to hands-on, targeted network intrusions; this is an assessment, not confirmation of a specific intrusion.
  • A later update reported similarities to Adaptix Agent and its adaptix_gopher protocol.
  • Reported indicators: SHA-256 f264f04f597a2bdda372a27ae701c18d4036175b1eb8722db5f8531615b38788; C2 iot.981666[.]xyz:8080; delivery URL zapier-logos.s3.amazonaws[.]com/gregbfdah.png.

Article Details

Attack Vectors
  • An ELF implant was delivered from the specified AWS-hosted URL; the article does not establish how a victim was induced to execute it.
  • When run with the -nodel argument, the implant daemonizes, profiles the host, and registers with a C2 server. Without that argument, it self-deletes.
  • C2 commands support program execution, file reads and writes, file exfiltration, permission and timestamp changes, and reverse tunnels for pivoting.
Defensive Notes
  • Investigate the identified ELF hash, delivery URL, and C2 host in relevant host and network telemetry.
  • The implant's host profiling, encrypted registration beacon, self-deletion behavior, and reverse-tunnel capability provide behaviors to investigate.

Indicators of compromise

TypeIndicatorContext
HOSTNAMEiot[.]981666[.]xyzC2 host listed with port 8080.
SHA256f264f04f597a2bdda372a27ae701c18d4036175b1eb8722db5f8531615b38788SHA-256 hash listed for the ELF implant.
URLhxxps[:]//zapier-logos[.]s3[.]amazonaws[.]com/gregbfdah[.]pngSpecific AWS-hosted URL identified as delivering the ELF implant.

MITRE ATT&CK

Vendors

Products

Tools

Related Articles