NOTROBIN

Aliases: remove_bds

First seen
2019-12-10 00:00:00
Malware type
backdoor
Profile updated
2026-07-07 12:57:42

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

FireEye states that NOTROBIN is a utility written in Go 1.10 and compiled to a 64-bit ELF binary for BSD systems. It periodically scans for and deletes files matching filename patterns and content characteristics. The purpose seems to be to block exploitation attempts against the CVE-2019-19781 vulnerability; however, FireEye believes that NOTROBIN provides backdoor access to the compromised system.

Exploited vulnerabilities

  • CVE-2019-19781 (vulnerability)

Reports & references

  • theregister.co.uk — Hackers Patch Citrix Vulnerability (report)
  • Mandiant — Vigilante Deploying Mitigation For Citrix Netscaler Vulnerability While Maintaining Backdoor (report)
  • intezer.com — Top Linux Cloud Threats Of 2020 (report)
  • intezer.com — Elf Malware Analysis 101 Linux Threats No Longer An Afterthought (report)
  • news.sophos.com — Asnarok2 (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Notrobin (report)
  • Mandiant — Rough Patch Promise It Will Be 200 Ok (report)
  • blog.dcso.de — A Curious Case Of Cve 2019 19781 Palware Remove Bds (report)
  • dcso.de — A Curious Case Of Cve 2019 19781 Palware Remove Bds (report)

External references