A Look Into Fysbis: Sofacy’s Linux Backdoor - Palo Alto Networks BlogPalo Alto Networks Blog
ID: 4c7cea98-34b8-4dee-8f9d-79d76c91d5c3
STIX ID: report--4c7cea98-34b8-4dee-8f9d-79d76c91d5c3
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2016-02-15
Last Modified Date: 2016-02-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 analyzes Fysbis, a modular Linux trojan/backdoor attributed to the Sofacy (APT28/Sednit) group, detailing three ELF samples (32- and 64-bit), their installation behaviors (root and non-root persistence paths), a rolling double-XOR decoding routine for install paths and C2 configuration, and associated infrastructure such as azureon-line.com, mozilla-plugins.com and IPs (e.g., 198.105.125.74, 104.207.130.126). The report provides IoCs (MD5/SHA256/ssdeep hashes, file paths, domains, and IPs), discusses implications for Linux security and detection challenges, and notes existing protections/signatures in Palo Alto Networks products.
