Rekoobe is a Linux backdoor derived from the open-source Tiny SHell codebase and observed in the wild since at least 2015. Written in C, it supports x86, x64, and SPARC architectures. Its core capabilities are file upload, file download, and remote command execution through an interactive shell, enabling file theft and deployment of additional payloads. Variants support outbound reverse-shell connections or inbound bind-shell access. Rekoobe has documented links to the China-based threat group APT31, also known as Zirconium, and has been deployed against Korean organizations and Linux servers.
Rekoobe protects command-and-control communications using AES-128 encryption and HMAC-SHA1-based key derivation and integrity checks. Analyzed builds embed connection details and authentication secrets in the executable. Process-name masquerading distinguishes Rekoobe from the original Tiny SHell implementation and helps it resemble legitimate system processes. A variant deployed alongside the Syslogk kernel rootkit operates as a fake SMTP server and opens a shell after receiving a specially crafted command over TLS; Syslogk supplies concealment and packet-triggered control of the backdoor process.
BPF-enabled Rekoobe variants have been observed in South Korean telecommunications and network-edge email-security environments. These builds impersonate SpamSniper components and inspect selected IPv4 and IPv6 traffic associated with SMTP using Berkeley Packet Filter functionality. Analyzed implementations authenticate activation traffic, conceal strings, suppress shell-history recording, and establish reverse-shell connections while masquerading as legitimate appliance services.
Rekoobe has also been delivered through software supply-chain attacks, including a malicious Go module impersonating a legitimate cryptographic library. In that campaign, credential harvesting and shell-script staging preceded installation of Rekoobe; those upstream components, rather than the backdoor itself, added attacker SSH access and weakened firewall policies.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This malware bears similarities to Rekoobe Malware, which is commonly used by APT31.
This malware bears similarities to Rekoobe Malware, which is commonly used by APT31.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Rekoobe is a backdoor known to be used by APT31, a threat group based in China.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
Additionally, there have been reported cases of supply chain attacks where a threat actor targeted a popular WordPress plugin and installed Rekoobe to gain control over compromised systems.
"adding a threat actor's SSH key to the 'authorized_keys' file"
BPFDoor and Rekoobe samples wait for a magic packet before opening interactive access.
Adore-Ng is a relatively old, open-source, well-known kernel rootkit for Linux... It enables hiding processes, files, and even the kernel module... In this post, we refer to this rootkit as Syslogk rootkit.
Strings are hidden with a rotating substitution alphabet.
Rekoobe disguises itself by changing its process name to “/bin/bash”, which matches the name of a normal process.
The common thread is regionalized disguise: each sample is aware of the vendor’s software running on the targeted systems and implements process spoofing accordingly.
The SpamSniper /var/run/spamsniper.pid mutex, together with the sample provenance, ties this build to the South Korean cluster.
“downloads additional payloads… while disguising them with the .mp5 extension”
"executes them, and deletes them from disk to reduce forensic evidence."
VIMINIT="set viminfo=", HISTFILE=/dev/null, HISTSIZE=0, and HISTFILESIZE=0.
That key seeds RC4's key-scheduling algorithm, and the resulting S-box is used directly as a keystream.
BPFDoor and Rekoobe samples wait for a magic packet before opening interactive access.
First, it checks whether the packet is a TCP packet and, in that case, it also checks the source port, which is expected to be 59318. Rekobee will be executed by the rootkit if the magic packet fits the mentioned criteria.
The BPFDoor variants create a raw PF_PACKET socket, attaching a classic BPF filter.
The malicious payload is hidden from tools like Netstat; when running, it will not appear in the list of services. For this purpose, the rootkit uses the function hk_t4_seq_show.
“exfiltrates passwords via HTTP POST… fetches a GitHub hosted ‘update’ resource”
Depending on the value of this 1 byte, three different commands can be performed: file upload, file download, or reverse shell execution.
BPFDoor and Rekoobe samples wait for a magic packet before opening interactive access.
First, it checks whether the packet is a TCP packet and, in that case, it also checks the source port, which is expected to be 59318. Rekobee will be executed by the rootkit if the magic packet fits the mentioned criteria.
The BPFDoor variants create a raw PF_PACKET socket, attaching a classic BPF filter.
It is a compiled backdoor trojan written in C programming language... widely known as the Rekoobe malware family... embedded in a fake SMTP server, which spawns a shell when it receives a specially crafted command.
It looks like an innocent SMTP server, but there is a backdoor command on it that can be executed when handling the starttls command... For triggering the Rekoobe backdoor command (spawning a shell), the attacker must send the byte 0x03 via TLS...
105 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A BPF-enabled Rekoobe variant observed against South Korean targets. It intercepts IPv4 TCP, UDP and SCTP traffic and IPv6 UDP traffic with source and destination ports equal to 25, and disguises its processes as SpamSniper components. Rekoobe logic is also described as integrated into the modular BPFDoor framework.
A Rekoobe-based Linux BPF backdoor deployed against South Korean targets. The observed build intercepts specified IPv4 and IPv6 traffic using port 25 and disguises its processes as SpamSniper components. Rekoobe logic is also described as integrated into BPFDoor's modular framework to support exfiltration.
Remote access Trojan used in a Linux implant campaign alongside BPFdoor. The reported variants imitate SpamSniper anti-spam software and legitimate background processes to conceal their presence on network-edge appliances.
The analyzed Linux variant passively monitors traffic with a BPF filter and authenticates magic packets before enabling remote access. It disguises processes as SpamSniper services, uses XOR-obfuscated strings and Tiny Shell/Rekoobe command semantics with HMAC-SHA1 and AES-CBC, and connects reverse shells to attacker port 25. It suppresses shell history and vim logging to reduce forensic evidence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.