xzbot
Aliases: xzorcist
- First seen
- 2023-07-01 00:00:00
- Malware type
- backdoor
- Profile updated
- 2026-07-07 14:41:14
Targeted industries: technology-and-telecommunications government-and-public-sector
Context
A backdoor brought into version 5.6.0 and 5.6.1 of compression library/tool xz/liblzma, which was intended to enable access via (Open)SSH on affected servers.
Exploited vulnerabilities
- CVE-2024-3094 (vulnerability)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Sh.Xzbot (report)
- github.com — Xzbot (report)
- openwall.com — 4 (report)
- github.com — Xz Malware (report)
- linkedin.com — Threatmon Xz Utils Backdoor Cve 2024 3094 Activity 7181228442791641088 Rw2A (report)
- sentinelone.com — Xz Utils Backdoor Threat Actor Planned To Inject Further Vulnerabilities (report)
- boehs.org — Everything I Know About The Xz Backdoor (report)
- gist.github.com — 223949D5A074Ebc3Dce9Ee78Baad9E27 (report)
- gynvael.coldwind.pl (report)
- twitter.com — 1774342248437813525 (report)
- CISA — Reported Supply Chain Compromise Affecting Xz Utils Data Compression Library Cve 2024 3094 (report)
- gist.github.com — A6112D54777845D389Bd7126D6E9F504 (report)
- wired.com — Jia Tan Xz Backdoor (report)
- medium.com — Xz Backdoor How To Check If Your Systems Are Affected Fb169B638271 (report)