APT41__2021__Linux_Backdoor_RedXOR_Likely_Operated_by_Chinese_Nation-State.pdf
ID: 778fc305-c2b4-4882-805f-d52defb1d9e3
STIX ID: report--778fc305-c2b4-4882-805f-d52defb1d9e3
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2021-03-12
Last Modified Date: 2021-03-12
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Executive summary: Intezer discovered and analyzed RedXOR, a sophisticated Linux backdoor (masquerading as a polkit daemon) that uses an open-source LKM rootkit (adore-ng), XOR-based network encoding, a Python pty shell, persistence via init scripts, and a port-mapping tunnel; the report attributes RedXOR to Chinese nation-state actors (links to Winnti/PWNLNX), provides configuration/communication details, commands, IOCs (hashes, domains, IPs, file paths), and detection/response guidance.
