QUIETEXIT is a stealthy backdoor and tunneling malware associated with the UNC3524 espionage cluster and tentatively linked in some reporting to APT29, the Russia-aligned SVR espionage actor also known as Cozy Bear. It has been used to maintain persistent access on embedded network devices, particularly VPN appliances and other opaque or weakly monitored systems, enabling long-term covert operations against enterprise email environments including Microsoft 365 and on-premises Microsoft Exchange.
The malware is notable for reversing traditional SSH client-server roles through an inverse negotiated SSH connection, allowing compromised devices to establish covert command-and-control channels that are difficult to distinguish from legitimate administrative traffic. QUIETEXIT can establish TCP connections to command-and-control infrastructure, proxy traffic via SOCKS, and fall back to a secondary hard-coded command-and-control endpoint if the primary one is unavailable. This tunneling capability supports operator access while minimizing the need to deploy additional tooling inside victim environments.
Operationally, QUIETEXIT has been used to help adversaries live off the land and evade detection by residing on embedded appliances and other systems that often lack endpoint security visibility. Samples have attempted to masquerade as benign system components, including by adopting names such as cron, to blend into the host environment. In UNC3524 intrusions, the malware supported prolonged dwell time and facilitated access to victim mail systems for bulk email collection and intelligence gathering, with targeting that included executive leadership, corporate development and mergers-and-acquisitions personnel, and IT security staff.
QUIETEXIT is best characterized as a covert access backdoor for espionage operations rather than a commodity malware family. Its tradecraft emphasizes persistence, defense evasion, and proxy-enabled remote access from network blind spots, especially on embedded Linux-based or appliance-class systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC3524 campaigns facilitate bulk email collection from victim environments... this threat actor leveraged a Dropbear-based backdoor, dubbed QUIETEXIT, on embedded network devices (such as VPN appliances) to access MS Office 365 or on-premises MS Exchange emails.
"The threat actor’s use of the QUIETEXIT tunneler allowed them to largely live off the land..."
20 distinct techniques documented for this family, organized by ATT&CK tactic.
"Find QUIETEXIT persistence mechanisms in the appliance’s rc.local directory..." and "MITRE ATT&CK... Persistence... T1037.004: RC Scripts"
Scheduled Task/Job (T1053): APT29 installs persistence mechanisms such as scheduled tasks or startup scripts.
"Find QUIETEXIT persistence mechanisms in the appliance’s rc.local directory..." and "MITRE ATT&CK... Persistence... T1037.004: RC Scripts"
MITRE ATT&CK Mappings: APT29 Defense Evasion T1027: Obfuscated Files or Information .001: Binary Padding .002: Software Packing .003: Steganography .005: Indicator Removal from Tools .006: HTML Smuggling
"MITRE ATT&CK... Command and Control... T1071: Application Layer Protocol"
UNC3524 usually accessed its victim's system from other compromised devices, usually outdated and unpatched LifeSize conference IoT cameras.
"MITRE ATT&CK... Command and Control... T1095: Non-Application Layer Protocol"
"The threat actor’s use of the QUIETEXIT tunneler..." and "MITRE ATT&CK... Command and Control... T1572: Protocol Tunneling"
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor-like SSH tunneling tool that inverts client-server roles to provide covert access, with execution sometimes ensured via startup scripts.
QUIETEXIT is a Dropbear-based backdoor used on embedded network devices such as VPN appliances to enable access to Office 365 or on-premises Exchange email for bulk email collection in espionage campaigns tentatively attributed to APT29.
Malware/tool that can proxy traffic over SOCKS.
Uses a second hard-coded C2 address if the first fails.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.