MINOCAT

First seen
2023-09-15 00:00:00
Malware type
trojan
Last IoC activity
2026-06-10 16:55:55
Profile updated
2026-07-07 13:16:42

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

According to Google, MINOCAT is an 64-bit ELF executable for Linux that includes a custom "NSS" wrapper and an embedded, open-source Fast Reverse Proxy (FRP) client that handles the actual tunneling.

Exploited vulnerabilities

  • CVE-2025-55182 (vulnerability)

Reports & references

  • cloud.google.com — Threat Actors Exploit React2Shell Cve 2025 55182 (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Minocat (report)

External references