xzbot

Aliases: xzorcist

First seen
2023-07-01 00:00:00
Malware type
backdoor
Profile updated
2026-07-07 14:41:14

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

A backdoor brought into version 5.6.0 and 5.6.1 of compression library/tool xz/liblzma, which was intended to enable access via (Open)SSH on affected servers.

Exploited vulnerabilities

  • CVE-2024-3094 (vulnerability)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Sh.Xzbot (report)
  • github.com — Xzbot (report)
  • openwall.com — 4 (report)
  • github.com — Xz Malware (report)
  • linkedin.com — Threatmon Xz Utils Backdoor Cve 2024 3094 Activity 7181228442791641088 Rw2A (report)
  • sentinelone.com — Xz Utils Backdoor Threat Actor Planned To Inject Further Vulnerabilities (report)
  • boehs.org — Everything I Know About The Xz Backdoor (report)
  • gist.github.com — 223949D5A074Ebc3Dce9Ee78Baad9E27 (report)
  • gynvael.coldwind.pl (report)
  • twitter.com — 1774342248437813525 (report)
  • CISA — Reported Supply Chain Compromise Affecting Xz Utils Data Compression Library Cve 2024 3094 (report)
  • gist.github.com — A6112D54777845D389Bd7126D6E9F504 (report)
  • wired.com — Jia Tan Xz Backdoor (report)
  • medium.com — Xz Backdoor How To Check If Your Systems Are Affected Fb169B638271 (report)

External references