Skip to content
New SysUpdate Variant Malware Discovered, Decryption Tool for Linux C2 Traffic Released

New SysUpdate Variant Malware Discovered, Decryption Tool for Linux C2 Traffic Released

Gbhackers •Mayura Kathir • February 18, 2026

A new Linux malware sample that strongly aligns with the SysUpdate malware family used by APT27/Iron Tiger. Initially detected on a client’s system, the binary behaved like a system service and executed the GNU/Linux id command when run without specific arguments, returning the output as part of its basic functionality. Closer inspection showed that the sample was […]

Extracted Entities

APT Groups (2)

Attack Types (1)

Malware (1)

Platforms (1)