logo

APT41__2021__Linux_Backdoor_RedXOR_Likely_Operated_by_Chinese_Nation-State.pdf

ID: 778fc305-c2b4-4882-805f-d52defb1d9e3

STIX ID: report--778fc305-c2b4-4882-805f-d52defb1d9e3

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2021-03-12

Last Modified Date: 2021-03-12

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Executive summary: Intezer discovered and analyzed RedXOR, a sophisticated Linux backdoor (masquerading as a polkit daemon) that uses an open-source LKM rootkit (adore-ng), XOR-based network encoding, a Python pty shell, persistence via init scripts, and a port-mapping tunnel; the report attributes RedXOR to Chinese nation-state actors (links to Winnti/PWNLNX), provides configuration/communication details, commands, IOCs (hashes, domains, IPs, file paths), and detection/response guidance.