SpeakUp is a Linux-focused malware family associated with opportunistic exploitation of vulnerable enterprise server software to execute malicious scripts and establish command-and-control. It has been observed attempting to exploit multiple publicly known server-side vulnerabilities, including flaws affecting Oracle WebLogic, Apache Struts, Apache ActiveMQ, JBoss application servers, and Hadoop YARN ResourceManager, indicating a strong emphasis on internet-facing server compromise and automated propagation across exposed infrastructure.
The malware uses Perl-based scripting as a core execution mechanism and performs host reconnaissance after compromise, including collecting user context with whoami and network configuration details with ifconfig. It also checks for the availability of specific ports on servers, consistent with service discovery and follow-on targeting of additional systems or services. Command-and-control communications are obfuscated with Base64 encoding. SpeakUp also deletes files to remove evidence from compromised machines, reflecting anti-forensic and defense-evasion behavior.
The observed tradecraft is consistent with a server-oriented post-exploitation implant or backdoor used in campaigns targeting Linux environments, particularly exposed application and middleware servers. Its behavior combines exploitation of known vulnerabilities, script-based execution, reconnaissance, encoded C2 traffic, and cleanup actions to support continued malicious operations on compromised hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
SpeakUp attempts to exploit the following vulnerabilities... CVE-2017-10271...
SpeakUp attempts to exploit the following vulnerabilities... CVE-2012-0874...
SpeakUp attempts to exploit the following vulnerabilities... CVE-2010-1871...
SpeakUp attempts to exploit the following vulnerabilities... CVE-2016-3088...
SpeakUp attempts to exploit the following vulnerabilities... CVE-2018-2894...
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries.
Fox Kitten has used a Perl reverse shell to communicate with C2. P.A.S. Webshell has the ability to create reverse shells with Perl scripts. SpeakUp uses Perl scripts. Windigo has used a Perl script for information gathering.
Several entries explicitly reference execution of built-in commands to obtain user context, e.g., “uses the Windows command "cmd.exe" /C whoami”, “has executed the whoami command”, “runs whoami and query user commands”, “used whoami and query user”.
During Cutting Edge, threat actors used Perl scripts to enable the deployment of the THINSPOOL shell script dropper and for enumerating host data. Fox Kitten has used a Perl reverse shell to communicate with C2. P.A.S. Webshell has the ability to create reverse shells with Perl scripts. Windigo has used a Perl script for information gathering.
"...leveraged the Chrome vulnerability, CVE-2022-0609, in combination with a Drive-by Compromise website." / "...has exploited client software vulnerabilities for execution..." / "...has used multiple software exploits for common client software...to gain code execution."
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include deleting tools, logs, malware-related files, staged archives, screenshots, temporary files, and exfiltrated data 'to cover their tracks,' 'reduce their footprint,' 'remove traces of activity,' or as part of 'post-intrusion cleanup.'
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes threat actors and malware performing network scanning, port scanning, service enumeration, OS fingerprinting, and identifying open ports/services across victim environments.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor that uses whoami for user discovery.
Uses ifconfig -a to enumerate network configuration.
Backdoor malware that deletes files to remove evidence.
Uses whoami to identify the current user.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.