Fysbis is a modular Linux backdoor used by Sofacy, also known as APT28 or Sednit, in cyberespionage operations. It forms part of the Russia-linked group's tooling for compromising Linux systems; Sofacy's broader targeting includes government and defense organizations, particularly in Eastern Europe. Fysbis implements plug-in and controller modules as distinct classes and exists as both 32-bit and 64-bit ELF binaries, with analyzed samples dating from late 2014 through late 2015.
The malware supports remote shell functionality, keylogging, discovery of running processes, and file deletion. It can install and establish persistence with or without root privileges, allowing operation under an ordinary user account. It disguises itself as legitimate synchronization, desktop notification, or system services. Fysbis communicates with command-and-control infrastructure and can Base64-encode its traffic. Later analyzed variants use a rolling double-XOR algorithm to obfuscate installation details and command-and-control configuration. Its relatively simple implementation nevertheless provides effective remote access and surveillance capabilities on compromised Linux systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
...the most recent ELF 64-bit binary... demonstrated minor evolution of the threat, most notably in terms of obfuscation... the referenced byte mask is applied to the other byte arrays using a rolling double-XOR algorithm to construct malware installation paths, filenames, and descriptions... The same masking method is also used by the binary to decode malware configuration C2 information...
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
C2 azureon-line[.]com (TCP/80) ... 198.105.125[.]74 (TCP/80) ... mozilla-plugins[.]com (TCP/80) | C2 azureon-line[.]com (TCP/80) ... C2 198.105.125[.]74 (TCP/80) ... C2 mozilla-plugins[.]com (TCP/80) ... The oldest sample... was found to beacon to the domain azureon-line[.]com... The first of the newer samples... beacons to an IP also widely associated with the Sofacy group... The newest sample... introduces a previously unknown command and control beacon to mozilla-plugins[.]com.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Drovorub, Fysbis, Downdelph, ADVSTORESHELL
Malware that impersonates trusted Linux software components.
Backdoor malware capable of deleting files.
Malware that can Base64-encode command-and-control traffic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.