Skip to content

Malware

B1txor20

B1txor20 is a malware that was discovered by 360 Netlab along others exploiting Log4J.

B1txor20 is a Linux malware family.

Background

B1txor20 was uncovered by 360 Netlab among the threats abusing Log4J. Its name comes from the "b1t" file name, the XOR encryption algorithm, and the 20-byte RC4 key length. 360 Netlab reports that this Linux backdoor relies on DNS tunneling to establish its C2 channel, and they suspected it was still under development given the presence of bugs and partially implemented features.


Source: Malpedia (Fraunhofer FKIE).