PWNLNX

First seen
2014-05-01 00:00:00
Malware type
backdoor, rat
Family
Malware family
Profile updated
2026-07-07 14:28:57

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

PWNLNX is a Linux-based malware that serves as a remote access tool with backdoor capabilities. It is mainly used for unauthorized access and persistence in targeted systems.

Detection coverage

  • 7 YARA rules

Detection rules

  • TRELLIX_ARC_Pwnlnx_Backdoor_Variant_1 (yara-rule)
  • TRELLIX_ARC_Pwnlnx_Backdoor_Variant_2 (yara-rule)
  • TRELLIX_ARC_Pwnlnx_Backdoor_Variant_3 (yara-rule)
  • TRELLIX_ARC_Pwnlnx_Backdoor_Variant_4 (yara-rule)
  • TRELLIX_ARC_Pwnlnx_Backdoor_Variant_6 (yara-rule)
  • TRELLIX_ARC_Mirai_Casper_Variant (yara-rule)
  • TRELLIX_ARC_APT_Stolen_Certificates (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Pwnlnx (report)
  • x.com — 1308740144120213506 (report)

External references