Skip to content
RedTail Malware Targets Linux Systems with Multi-Architecture Payloads

RedTail Malware Targets Linux Systems with Multi-Architecture Payloads

First seen 14 Sep 2026, 15:18 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 16:52 UTC
  • RedTail malware targets multiple Linux architectures, including ARM and x86-64.
  • It modifies crontabs and firewall rules to establish persistence and evade detection.
  • Dynamic analysis reveals its ability to terminate monitoring tools like strace.

The RedTail malware family has been identified as a multi-architecture threat targeting Linux systems. It employs various attack methods, including process masquerading and establishing persistence through crontab modifications. Dynamic analysis of an x86-64 variant revealed its capability to terminate monitoring processes and create unauthorized network connections. The malware operates over DNS-over-TLS on TCP port 853, complicating detection efforts. Security teams are advised to monitor for suspicious process behavior and implement strict access controls. The malware's deployment package includes architecture-specific executables and scripts for installation and cleanup. Organizations should isolate affected systems immediately upon detection to prevent lateral movement. Current status indicates ongoing analysis and response efforts to mitigate the threat.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-09
RedTail payload observed
An intern at ISC detected RedTail malware during honeypot monitoring, revealing multiple architecture-specific executables.
Isc.Sans.Edu
2026-09-10
Dynamic analysis conducted
The x86-64 variant of RedTail was analyzed in an isolated environment, showing malicious behavior including process termination and network socket creation.
Isc.Sans.Edu
2026-09-12
RedTail behavior detailed
Socprime published an analysis highlighting RedTail's capabilities, including process masquerading and persistence mechanisms.
Socprime

More articles in this cluster (2)

Following this threat?

Track RedTail and Ubuntu in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed