Linux that was assumed to be "safe" from malware is getting attention from attackers. RedXOR is a Linux malware allegedly attributed to Chinese hackers. RedXOR comes with a large set of capabilities, including executing commands with system privileges, managing files on infected Linux boxes, hiding its process using the Adore-ng open-source rootkit, proxy-ing malicious traffic and remote updating.
RedXOR Backdoor Sample 1 Signatures
Family: Trojan:Win32/Casdet!rfn
MD5: 2bd6e2f8c1a97347b1e499e29a1d9b7c
SHA256: 0a76c55fa88d4c134012a5136c09fb938b4be88a382f88bf2804043253b0559f
RedXOR Backdoor Sample 1 Download
RedXOR Backdoor Sample 2 Signatures
Family: Trojan:Win32/Casdet!rfn
MD5: 7351f8a40c5450557b24622417fc478d
SHA256: 0423258b94e8a9af58ad63ea493818618de2d8c60cf75ec7980edcaa34dcc919
RedXOR Backdoor Sample 2 Download