Socprime RedTail Malware Targets Linux Systems with Multi-Architecture Payloads
Article Content
- •RedTail malware targets multiple Linux architectures, including ARM and x86-64.
- •It modifies crontabs and firewall rules to establish persistence and evade detection.
- •Dynamic analysis reveals its ability to terminate monitoring tools like strace.
The RedTail malware family has been identified as a multi-architecture threat targeting Linux systems. It employs various attack methods, including process masquerading and establishing persistence through crontab modifications. Dynamic analysis of an x86-64 variant revealed its capability to terminate monitoring processes and create unauthorized network connections. The malware operates over DNS-over-TLS on TCP port 853, complicating detection efforts. Security teams are advised to monitor for suspicious process behavior and implement strict access controls. The malware's deployment package includes architecture-specific executables and scripts for installation and cleanup. Organizations should isolate affected systems immediately upon detection to prevent lateral movement. Current status indicates ongoing analysis and response efforts to mitigate the threat.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track RedTail and Ubuntu in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Massive Data Breach Exposes 220 Million Airline Records in Vietnam An exposed Advance Passenger Information System (APIS) database in Vietnam has leaked over 220 million records, including sensitive passenger and crew information such as passport numbers and flight details. Discovered by Kinryū Labs, the Elasticsearch cluster was accessible online due to a series of security…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…