REPTILE
MITRE ATT&CK: S1219 View on attack.mitre.org
Aliases: REPTILE
- Malware type
- rootkit, backdoor
- Family
- Malware family
- Operating systems
- linux
- Profile updated
- 2026-07-07 13:01:40
Context
REPTILE is an open-source Linux rootkit with multiple components that provides backdoor access and functionality.
Detection coverage
- 43 Sigma rules
Malware & tools used
- Launch Daemon (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Port Knocking (attack-pattern)
- Udev Rules (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Traffic Signaling (attack-pattern)
- Unix Shell (attack-pattern)
- Rootkit (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Kernel Modules and Extensions (attack-pattern)
Used by threat actors
- RedPenguin (campaign)
- UNC3886 (threat-actor)
Reports & references
- Trend Micro — Wp Operation Earth Berberoka (report)
- botconf.eu — Botconf2022 40 Lunghihorejsi (report)
- asec.ahnlab.com — 55785 (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Reptile (report)
- dfir.ch — Reptile Launcher (report)
- cloud.google.com — China Nexus Espionage Targets Juniper Routers (report)
- github.com — Reptile (report)
- cloud.google.com — Uncovering Unc3886 Espionage Operations (report)
- MITRE ATT&CK — S1219 (report)