Xnote is a Linux backdoor observed in the wild since 2015. It provides remote control of compromised Linux servers and is deployed as part of post-compromise toolsets. A variant used by the intrusion cluster CL-UNK-1068 includes distributed denial-of-service (DDoS) capabilities in addition to backdoor commands.
Xnote has been used by multiple threat actors, including Earth Berberoka, also known as GamblingPuppet, in attacks against online gambling sites; CL-UNK-1068 in intrusions affecting critical infrastructure and government-related organizations across South, Southeast, and East Asia; and UTG-Q-015 to control compromised Linux servers. UTG-Q-015's Linux targeting in 2025 included AI research environments. Xnote is deployed alongside other backdoors, web shells, and tunneling utilities, and its use is not exclusive to a single actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UTG-Q-015 generally use Xnote, Ghost, Vshell and other backdoors to control the target linux servers, and the targets in 2025 are mainly focused on the AI field.
Xnote, a Linux backdoor tied to the group, was reported in March during attacks on critical infrastructure in Asia.
Xnote, a Linux backdoor tied to the group, was reported in March during attacks on critical infrastructure in Asia.
Further, to maintain command-and-control (C2) access and bypass network controls, the actor also deploys modified builds of Fast Reverse Proxy (FRP) and occasionally installs the Xnote Linux backdoor.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux backdoor tied to the group and reportedly used in attacks against Asian critical infrastructure.
Linux backdoor used to provide unauthorized remote access on compromised Linux systems.
Linux backdoor used to maintain persistent remote access and support command-and-control on compromised Linux hosts.
Linux backdoor (first reported 2015) used here primarily for DDoS capabilities plus file operations, reverse shell, port forwarding, and reverse proxy/tunneling tasks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.