Cybersecuritynews
New SysUpdate Malware Variant Targets Linux with Encrypted C2 Traffic
First seen 18 Feb 2026, 16:24 UTC
•

•85% similarity
•30.6
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A new variant of SysUpdate malware has been identified, specifically targeting Linux systems with advanced command-and-control (C2) encryption. This malware was discovered during a Digital Forensics and Incident Response engagement, where a suspicious ELF64 executable was found in a client's environment. The malware mimics system service behavior and executes basic commands, indicating its operational capabilities.
ThreatCluster AI
How this analysis works
Timeline
2026-02-18
New SysUpdate variant malware discovered
2026-02-18
Decryption tool for Linux C2 traffic released