MINOCAT
- First seen
- 2023-09-15 00:00:00
- Malware type
- trojan
- Last IoC activity
- 2026-06-10 16:55:55
- Profile updated
- 2026-07-07 13:16:42
Targeted industries: technology-and-telecommunications government-and-public-sector
Context
According to Google, MINOCAT is an 64-bit ELF executable for Linux that includes a custom "NSS" wrapper and an embedded, open-source Fast Reverse Proxy (FRP) client that handles the actual tunneling.
Exploited vulnerabilities
- CVE-2025-55182 (vulnerability)
Reports & references
- cloud.google.com — Threat Actors Exploit React2Shell Cve 2025 55182 (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Minocat (report)