Skip to content

Malware

RedXOR

RedXOR is a sophisticated backdoor targeting Linux systems disguised as polkit daemon and utilizing network data encoding based on XOR.

RedXOR is a Linux malware family.

Background

RedXOR is an advanced backdoor aimed at Linux hosts that masquerades as the polkit daemon and obscures its network traffic using XOR-based encoding. Thought to be the work of Chinese state-sponsored actors, it bears resemblance to other tooling tied to the Winnti umbrella group. The malware leans on techniques such as open-source LKM rootkits, a Python pty shell, and XOR-encoded network data, while also maintaining persistence and talking to its Command and Control server over HTTP. Its supported commands range from gathering system information and self-updating to running shell commands and tunneling network traffic.


Source: Malpedia (Fraunhofer FKIE).