Melofee: a look back at a Linux implant and its new variants
Melofee is a Linux implant malware that has evolved over three years to include a modular architecture with hot-loadable components for shell access, file management, and command execution. It incorporates a kernel rootkit based on the Reptile project for enhanced stealth and supports multiple communication protocols with RC4 encryption. The malware uses fake certificates to impersonate trusted entities and is linked by code similarities to Windows implants used by Chinese state-linked groups. Its modular design allows dynamic loading of up to eleven specialized modules via a common plugin interface.
AI Analysis
Technical Summary
Melofee is a sophisticated Linux implant malware that has evolved to feature a modular architecture enabling dynamic loading of multiple specialized modules for various functionalities such as shell access, file management, and command execution. It employs a kernel rootkit derived from the Reptile project to enhance stealth capabilities. Communications are encrypted with RC4 and utilize multiple protocols including TCP, HTTP, HTTPS, and TLS. Analysis identified two infrastructure clusters using fake certificates impersonating Symantec and other entities. Code similarities link Melofee to Windows-targeting implants like CrowDoor, Hemigate, and RatelS, indicating shared tooling among Chinese state-linked threat actors.
Potential Impact
The implant provides attackers with persistent, stealthy access to compromised Linux systems, enabling remote command execution, file management, and system control. Its kernel rootkit enhances evasion from detection. The use of fake certificates and multiple communication protocols complicates network detection and attribution. The linkage to other implants used by Chinese state-linked groups suggests a coordinated threat actor infrastructure with potentially broad targeting and operational scope.
Mitigation Recommendations
No specific patch or remediation is indicated for Melofee as it is malware rather than a software vulnerability. Mitigation should focus on detection and removal using updated endpoint protection solutions and network monitoring for indicators of compromise such as suspicious certificates and unusual encrypted traffic patterns. Incident response should consider the modular nature and stealth techniques of the implant. There is no vendor patch or official fix since this is malware.
Indicators of Compromise
- ip: 92.38.169.152
- ip: 185.163.2.79
- domain: blog.exatrack.com
- ip: 45.67.230.185
- domain: blog-en.itochuci.co.jp
- domain: www.windefender.net
- domain: windefender.net
- ip: 180.149.44.115
- ip: 185.163.2.34
- ip: 38.54.110.44
- ip: 130.94.91.165
- ip: 103.215.216.117
- ip: 89.44.198.107
- domain: microsoftupdates.top
- ip: 103.215.216.181
- ip: 185.163.2.100
- ip: 103.215.216.61
- ip: 185.163.2.81
- ip: 146.71.85.33
- hash: 40637c70fd5cd899ca41d1252c267ccf
- hash: 71d3832587a1d009ca3c0947005b187f23e52008
- hash: b6df18f66cf4364be2946d6b981e69763aafde68
- hash: dbbcb279a1f1a258832174ce63c295c5080de249
- hash: 0c1666b274ddb44dd5c7a11f03c8c041f6bccf0c7dae924626ef9d15b1cc41d5
- hash: 129349a221e6efcc9a047efdfd81197f796fcf38877344f17f85651b21e33427
- hash: 4400096e8b39cb2641abec17c6dddad845ed6415e79d60adc2af1dcbd2837c59
- hash: 50daadd49b8df4f0190d0badfde89f8e6a6e61af664ef1444984028a005f40d8
- hash: 6678216ace0ff224d6a5ae6bf1ca29e66fba9fceaa715e27440e85d5bfb06069
- hash: 8255d5a423ce79c69e42685cbf8e708b4239650c01b2898a7efe856582bb3aaf
- hash: 9d01724193d9570a6c75bbcbb171d29df290207007d004cf75d133dd9aa475f4
- hash: aa2fd252a6f5a09b8d8422fbd1037febefe2aa99317e3c3973889384a80e29b7
- hash: cbce7dc8649b37c5db411dfee3a74e8cace2b48fdc8350bfa5b4846c5d9ed2ae
- hash: dd081c130d7c3a3c18e06a26300dcfd65ee70e6b23b729edb54cb0f0a5829df9
- ip: 103.215.216.116
- ip: 103.215.216.162
- ip: 103.215.216.27
- ip: 103.215.216.75
- ip: 103.87.9.148
- ip: 130.94.91.53
- ip: 154.205.137.88
- ip: 180.149.44.110
- ip: 180.149.44.43
- ip: 2.56.166.139
- ip: 2.56.166.84
- ip: 38.54.71.107
- ip: 38.54.71.56
- ip: 45.80.208.232
- url: http://windefender.net:443
- url: http://windowsupdates.us:80
- url: http://www.windefender.net:443
- hash: c8e585c8a161b9b7a0e59bd65a3ec5492375d53c
- domain: amzaonaws.org
- domain: microupdate.me
- domain: microupdate.top
- domain: windowsupdates.us
- domain: awsclouds.awspull.com
- domain: documentation.stormshield.eu
- domain: update.miss-soft.com
- domain: update.wwwubuntu.com
- domain: www.partow.net
Melofee: a look back at a Linux implant and its new variants
Description
Melofee is a Linux implant malware that has evolved over three years to include a modular architecture with hot-loadable components for shell access, file management, and command execution. It incorporates a kernel rootkit based on the Reptile project for enhanced stealth and supports multiple communication protocols with RC4 encryption. The malware uses fake certificates to impersonate trusted entities and is linked by code similarities to Windows implants used by Chinese state-linked groups. Its modular design allows dynamic loading of up to eleven specialized modules via a common plugin interface.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Melofee is a sophisticated Linux implant malware that has evolved to feature a modular architecture enabling dynamic loading of multiple specialized modules for various functionalities such as shell access, file management, and command execution. It employs a kernel rootkit derived from the Reptile project to enhance stealth capabilities. Communications are encrypted with RC4 and utilize multiple protocols including TCP, HTTP, HTTPS, and TLS. Analysis identified two infrastructure clusters using fake certificates impersonating Symantec and other entities. Code similarities link Melofee to Windows-targeting implants like CrowDoor, Hemigate, and RatelS, indicating shared tooling among Chinese state-linked threat actors.
Potential Impact
The implant provides attackers with persistent, stealthy access to compromised Linux systems, enabling remote command execution, file management, and system control. Its kernel rootkit enhances evasion from detection. The use of fake certificates and multiple communication protocols complicates network detection and attribution. The linkage to other implants used by Chinese state-linked groups suggests a coordinated threat actor infrastructure with potentially broad targeting and operational scope.
Defensive Guidance
No specific patch or remediation is indicated for Melofee as it is malware rather than a software vulnerability. Mitigation should focus on detection and removal using updated endpoint protection solutions and network monitoring for indicators of compromise such as suspicious certificates and unusual encrypted traffic patterns. Incident response should consider the modular nature and stealth techniques of the implant. There is no vendor patch or official fix since this is malware.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.stormshield.com/news/cti-melofee-linux-implant-and-new-variants/"]
- Adversary
- APT41
- Pulse Id
- 6aa32c68adf3f06777eb0318
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip92.38.169.152 | — | |
ip185.163.2.79 | — | |
ip45.67.230.185 | — | |
ip180.149.44.115 | — | |
ip185.163.2.34 | — | |
ip38.54.110.44 | — | |
ip130.94.91.165 | — | |
ip103.215.216.117 | — | |
ip89.44.198.107 | — | |
ip103.215.216.181 | — | |
ip185.163.2.100 | — | |
ip103.215.216.61 | — | |
ip185.163.2.81 | — | |
ip146.71.85.33 | — | |
ip103.215.216.116 | — | |
ip103.215.216.162 | — | |
ip103.215.216.27 | — | |
ip103.215.216.75 | — | |
ip103.87.9.148 | — | |
ip130.94.91.53 | — | |
ip154.205.137.88 | — | |
ip180.149.44.110 | — | |
ip180.149.44.43 | — | |
ip2.56.166.139 | — | |
ip2.56.166.84 | — | |
ip38.54.71.107 | — | |
ip38.54.71.56 | — | |
ip45.80.208.232 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainblog.exatrack.com | — | |
domainblog-en.itochuci.co.jp | — | |
domainwww.windefender.net | — | |
domainwindefender.net | — | |
domainmicrosoftupdates.top | — | |
domainamzaonaws.org | — | |
domainmicroupdate.me | — | |
domainmicroupdate.top | — | |
domainwindowsupdates.us | — | |
domainawsclouds.awspull.com | — | |
domaindocumentation.stormshield.eu | — | |
domainupdate.miss-soft.com | — | |
domainupdate.wwwubuntu.com | — | |
domainwww.partow.net | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash40637c70fd5cd899ca41d1252c267ccf | — | |
hash71d3832587a1d009ca3c0947005b187f23e52008 | — | |
hashb6df18f66cf4364be2946d6b981e69763aafde68 | — | |
hashdbbcb279a1f1a258832174ce63c295c5080de249 | — | |
hash0c1666b274ddb44dd5c7a11f03c8c041f6bccf0c7dae924626ef9d15b1cc41d5 | — | |
hash129349a221e6efcc9a047efdfd81197f796fcf38877344f17f85651b21e33427 | — | |
hash4400096e8b39cb2641abec17c6dddad845ed6415e79d60adc2af1dcbd2837c59 | — | |
hash50daadd49b8df4f0190d0badfde89f8e6a6e61af664ef1444984028a005f40d8 | — | |
hash6678216ace0ff224d6a5ae6bf1ca29e66fba9fceaa715e27440e85d5bfb06069 | — | |
hash8255d5a423ce79c69e42685cbf8e708b4239650c01b2898a7efe856582bb3aaf | — | |
hash9d01724193d9570a6c75bbcbb171d29df290207007d004cf75d133dd9aa475f4 | — | |
hashaa2fd252a6f5a09b8d8422fbd1037febefe2aa99317e3c3973889384a80e29b7 | — | |
hashcbce7dc8649b37c5db411dfee3a74e8cace2b48fdc8350bfa5b4846c5d9ed2ae | — | |
hashdd081c130d7c3a3c18e06a26300dcfd65ee70e6b23b729edb54cb0f0a5829df9 | — | |
hashc8e585c8a161b9b7a0e59bd65a3ec5492375d53c | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://windefender.net:443 | — | |
urlhttp://windowsupdates.us:80 | — | |
urlhttp://www.windefender.net:443 | — |
Threat ID: 6aa40d6691cc7f384843739f
Added to database: 09/11/2026, 14:17:10 UTC
Last enriched: 09/11/2026, 14:35:21 UTC
Last updated: 09/11/2026, 16:18:06 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.