Skip to main content

Melofee: a look back at a Linux implant and its new variants

0
Medium
Published: 09/10/2026 (09/10/2026, 22:17:12 UTC)
Source: AlienVault OTX General

Description

Melofee is a Linux implant malware that has evolved over three years to include a modular architecture with hot-loadable components for shell access, file management, and command execution. It incorporates a kernel rootkit based on the Reptile project for enhanced stealth and supports multiple communication protocols with RC4 encryption. The malware uses fake certificates to impersonate trusted entities and is linked by code similarities to Windows implants used by Chinese state-linked groups. Its modular design allows dynamic loading of up to eleven specialized modules via a common plugin interface.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/11/2026, 14:35:21 UTC

Technical Analysis

Melofee is a sophisticated Linux implant malware that has evolved to feature a modular architecture enabling dynamic loading of multiple specialized modules for various functionalities such as shell access, file management, and command execution. It employs a kernel rootkit derived from the Reptile project to enhance stealth capabilities. Communications are encrypted with RC4 and utilize multiple protocols including TCP, HTTP, HTTPS, and TLS. Analysis identified two infrastructure clusters using fake certificates impersonating Symantec and other entities. Code similarities link Melofee to Windows-targeting implants like CrowDoor, Hemigate, and RatelS, indicating shared tooling among Chinese state-linked threat actors.

Potential Impact

The implant provides attackers with persistent, stealthy access to compromised Linux systems, enabling remote command execution, file management, and system control. Its kernel rootkit enhances evasion from detection. The use of fake certificates and multiple communication protocols complicates network detection and attribution. The linkage to other implants used by Chinese state-linked groups suggests a coordinated threat actor infrastructure with potentially broad targeting and operational scope.

Defensive Guidance

No specific patch or remediation is indicated for Melofee as it is malware rather than a software vulnerability. Mitigation should focus on detection and removal using updated endpoint protection solutions and network monitoring for indicators of compromise such as suspicious certificates and unusual encrypted traffic patterns. Incident response should consider the modular nature and stealth techniques of the implant. There is no vendor patch or official fix since this is malware.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.stormshield.com/news/cti-melofee-linux-implant-and-new-variants/"]
Adversary
APT41
Pulse Id
6aa32c68adf3f06777eb0318

Indicators of Compromise

Ip

ValueDescriptionCopy
ip92.38.169.152
ip185.163.2.79
ip45.67.230.185
ip180.149.44.115
ip185.163.2.34
ip38.54.110.44
ip130.94.91.165
ip103.215.216.117
ip89.44.198.107
ip103.215.216.181
ip185.163.2.100
ip103.215.216.61
ip185.163.2.81
ip146.71.85.33
ip103.215.216.116
ip103.215.216.162
ip103.215.216.27
ip103.215.216.75
ip103.87.9.148
ip130.94.91.53
ip154.205.137.88
ip180.149.44.110
ip180.149.44.43
ip2.56.166.139
ip2.56.166.84
ip38.54.71.107
ip38.54.71.56
ip45.80.208.232

Domain

ValueDescriptionCopy
domainblog.exatrack.com
domainblog-en.itochuci.co.jp
domainwww.windefender.net
domainwindefender.net
domainmicrosoftupdates.top
domainamzaonaws.org
domainmicroupdate.me
domainmicroupdate.top
domainwindowsupdates.us
domainawsclouds.awspull.com
domaindocumentation.stormshield.eu
domainupdate.miss-soft.com
domainupdate.wwwubuntu.com
domainwww.partow.net

Hash

ValueDescriptionCopy
hash40637c70fd5cd899ca41d1252c267ccf
hash71d3832587a1d009ca3c0947005b187f23e52008
hashb6df18f66cf4364be2946d6b981e69763aafde68
hashdbbcb279a1f1a258832174ce63c295c5080de249
hash0c1666b274ddb44dd5c7a11f03c8c041f6bccf0c7dae924626ef9d15b1cc41d5
hash129349a221e6efcc9a047efdfd81197f796fcf38877344f17f85651b21e33427
hash4400096e8b39cb2641abec17c6dddad845ed6415e79d60adc2af1dcbd2837c59
hash50daadd49b8df4f0190d0badfde89f8e6a6e61af664ef1444984028a005f40d8
hash6678216ace0ff224d6a5ae6bf1ca29e66fba9fceaa715e27440e85d5bfb06069
hash8255d5a423ce79c69e42685cbf8e708b4239650c01b2898a7efe856582bb3aaf
hash9d01724193d9570a6c75bbcbb171d29df290207007d004cf75d133dd9aa475f4
hashaa2fd252a6f5a09b8d8422fbd1037febefe2aa99317e3c3973889384a80e29b7
hashcbce7dc8649b37c5db411dfee3a74e8cace2b48fdc8350bfa5b4846c5d9ed2ae
hashdd081c130d7c3a3c18e06a26300dcfd65ee70e6b23b729edb54cb0f0a5829df9
hashc8e585c8a161b9b7a0e59bd65a3ec5492375d53c

Url

ValueDescriptionCopy
urlhttp://windefender.net:443
urlhttp://windowsupdates.us:80
urlhttp://www.windefender.net:443

Threat ID: 6aa40d6691cc7f384843739f

Added to database: 09/11/2026, 14:17:10 UTC

Last enriched: 09/11/2026, 14:35:21 UTC

Last updated: 09/11/2026, 16:18:06 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses