RedXOR
- First seen
- 2021-02-01 00:00:00
- Malware type
- backdoor, rootkit
- Profile updated
- 2026-07-07 14:29:15
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
RedXOR is a sophisticated backdoor targeting Linux systems disguised as polkit daemon and utilizing network data encoding based on XOR. Believed to be developed by Chinese nation-state actors, this malware shows similarities to other malware associated with the Winnti umbrella threat group. RedXOR uses various techniques such as open-source LKM rootkits, Python pty shell, and network data encoding with XOR. It also employs persistence methods and communication with a Command and Control server over HTTP. The malware can execute various commands including system information collection, updates, shell commands, and network tunneling.
Detection coverage
- 1 YARA rules
Detection rules
- ARKBIRD_SOLG_MAL_Redxor_Feb_2021_1 (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Redxor (report)
- intezer.com — New Linux Backdoor Redxor Likely Operated By Chinese Nation State Actor (report)