RotaJakiro
MITRE ATT&CK: S1078 View on attack.mitre.org
Aliases: RotaJakiro
- First seen
- 2018-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- linux
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-07-18 06:30:45
- Profile updated
- 2026-07-07 14:29:29
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:vn
Context
RotaJakiro is a 64-bit Linux backdoor used by APT32. First seen in 2018, it uses a plugin architecture to extend capabilities. RotaJakiro can determine it's permission level and execute according to access type (`root` or `user`).
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to RotaJakiro (S1078). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 260325-ldk2qshy5q.bin | 2026-07-18 | 1 |
Detection coverage
- 1 YARA rules
- 98 Sigma rules
Malware & tools used
- Deobfuscate/Decode Files or Information (attack-pattern)
- Unix Shell Configuration Modification (attack-pattern)
- Native API (attack-pattern)
- Standard Encoding (attack-pattern)
- Boot or Logon Initialization Scripts (attack-pattern)
- System Information Discovery (attack-pattern)
- Systemd Service (attack-pattern)
- Shared Modules (attack-pattern)
- Non-Standard Port (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Inter-Process Communication (attack-pattern)
- Process Discovery (attack-pattern)
- Automated Collection (attack-pattern)
- XDG Autostart Entries (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Symmetric Cryptography (attack-pattern)
Used by threat actors
- APT32 (threat-actor)
Detection rules
- ARKBIRD_SOLG_MAL_ELF_Rotajakiro_May_2021_1 (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Rotajakiro (report)
- blog.netlab.360.com — Stealth Rotajakiro Backdoor En (report)
- blog.netlab.360.com — Rotajakiro Linux Version Of Oceanlotus (report)
- domaintools.com — Domaintools And Digital Archeology A Look At Rotajakiro (report)
- MITRE ATT&CK — S1078 (report)