PWNLNX
- First seen
- 2014-05-01 00:00:00
- Malware type
- backdoor, rat
- Family
- Malware family
- Profile updated
- 2026-07-07 14:28:57
Targeted industries: technology-and-telecommunications government-and-public-sector
Context
PWNLNX is a Linux-based malware that serves as a remote access tool with backdoor capabilities. It is mainly used for unauthorized access and persistence in targeted systems.
Detection coverage
- 7 YARA rules
Detection rules
- TRELLIX_ARC_Pwnlnx_Backdoor_Variant_1 (yara-rule)
- TRELLIX_ARC_Pwnlnx_Backdoor_Variant_2 (yara-rule)
- TRELLIX_ARC_Pwnlnx_Backdoor_Variant_3 (yara-rule)
- TRELLIX_ARC_Pwnlnx_Backdoor_Variant_4 (yara-rule)
- TRELLIX_ARC_Pwnlnx_Backdoor_Variant_6 (yara-rule)
- TRELLIX_ARC_Mirai_Casper_Variant (yara-rule)
- TRELLIX_ARC_APT_Stolen_Certificates (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Pwnlnx (report)
- x.com — 1308740144120213506 (report)