Threats Tagged 'linux toolkit'
View all threats tagged with 'linux toolkit'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'linux toolkit'
Click on any threat for detailed analysis and mitigation recommendations
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors 0 A previously undocumented Linux toolkit has been targeting South Korean automotive and media organizations with minimal detection since early 2025. The campaign employs a HAProxy instance called ted backdoor, compiled within the victim's existing HAProxy version 2.8.12, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This sophisticated framework enables remote command execution, malicious script injection into web traffic, credential harvesting, and long-term surveillance. The ted backdoor uses HAProxy's native filter API and internal structures to intercept SSL-decrypted HTTP traffic while maintaining legitimate load balancing operations. Operating alongside are an SSH keylogger, a curl-based RAT with HAProxy health monitoring capabilities, and a deployment stager. The toolkit is attributed with medium confidence to DPRK APTs based on targeting patterns, simple XOR-based encryption schemes, custom substitution ciphers, and C2 infrastructure associated with APT37. Join the discussion | AlienVault OTX General | 09/04/2026, 16:53:57 UTC Added: 09/07/2026, 10:22:27 UTC |
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon 0 Since mid-2025, a Chinese-speaking cybercrime group dubbed Gambling Goblin has conducted a sustained campaign targeting Brazilian organizations, mainly government and educational institutions. The attackers compromise web servers and install malicious Apache modules that stealthily reverse-proxy visitors to phishing pages impersonating trusted app stores. These phishing pages promote online gambling and sports betting while leveraging hijacked high-reputation domains to manipulate search engine rankings and hijack traffic. The group uses a heavily obfuscated Linux toolkit including downloaders, backdoors, credential stealers, and brute-forcers. The infrastructure is scalable and extends beyond Brazil, with parallel phishing networks targeting Vietnamese, Spanish, and English-speaking victims. The phishing infrastructure could be reconfigured to deliver malware directly, posing a latent escalation risk. Join the discussion | Check Point Research | 09/02/2026, 13:40:05 UTC Added: 09/02/2026, 10:30:02 UTC |
Showing 1 to 2 of 2 results