Linodas

Aliases: DinodasRAT, XDealer

First seen
2021-01-15 00:00:00
Malware type
rat
Family
Malware family
Last IoC activity
2026-07-21 08:35:51
Profile updated
2026-07-07 13:13:15

Targeted industries: government-and-public-sector financial-services technology-and-telecommunications

Targeted regions: country_code:us country_code:ru country_code:cn

Context

Linodas, also known as DinodasRAT and XDealer, is a remote access trojan (RAT) used for espionage and data exfiltration targeting government, financial, and technology sectors. It is notable for its sophisticated capabilities and focuses on infiltrating high-value targets.

Detection coverage

  • 4 YARA rules

Detection rules

  • SEKOIA_Apt_Implant_Xdealer_Stealer_Strings (yara-rule)
  • SEKOIA_Apt_Implant_Xdealer_Strings (yara-rule)
  • SEKOIA_Apt_Implant_Xdealer_Vbs_Launcher_Strings (yara-rule)
  • SEKOIA_Apt_Implant_Xdealer_Linux_Variant_Strings (yara-rule)

Reports & references

  • Trend Micro — Earth Krahang (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Linodas (report)
  • research.checkpoint.com — 29676 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Dinodas Rat (report)
  • ESET — Operation Jacana Spying Guyana Entity (report)

External references