Skip to content

Malware

Caja

Linux malware cross-compiled for x86, MIPS, ARM.

Caja is a Linux malware family operated by APT32.

Background

A piece of Linux malware cross-compiled to run on x86, MIPS, and ARM. Its strings are XOR-encoded, and its C&C supports 13 commands covering downloads, file modification and execution, and the running of shell commands.


Source: Malpedia (Fraunhofer FKIE).