Multiverze is a Linux trojan associated with TeamPCP activity and used against internet-exposed Linux servers, particularly systems with accessible SSH services. It has been described as an automated threat used to obtain shell access on vulnerable or weakly protected Linux hosts. The malware has been observed in the context of broader TeamPCP operations targeting cloud-native and developer environments, where compromised infrastructure is repurposed for follow-on intrusion activity.
Reported behavior indicates that Multiverze is used after initial compromise of Linux servers to support post-compromise operations. TeamPCP tradecraft linked to this activity includes credential harvesting, use of compromised hosts as proxy or scanning nodes, persistence deployment, and propagation-oriented behavior against additional victims. The surrounding campaigns have focused on cloud platforms, CI/CD environments, GitHub Actions runners, containers, and Kubernetes-connected infrastructure, suggesting operational interest in high-value developer and cloud workloads rather than conventional end-user systems.
Multiverze has been detected by Microsoft Defender for Endpoint under a MacOS trojan signature name, but the directly supported behavioral characterization identifies it as a Linux-focused trojan used against SSH-accessible servers. High-confidence reporting supports Linux targeting and SSH-based intrusion as the principal access vector. Broader attribution to TeamPCP places the malware within campaigns emphasizing automation, credential theft, reconnaissance, scanning, persistence, lateral movement in cloud-native environments, and exfiltration of sensitive material from compromised infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TeamPCP had made use of Multiverze — A Linux Trojan which is an automated threat that affects Linux servers running accessible SSH services as its main attack vector for Shells
Microsoft Defender for Endpoint – Trojan:MacOS/Multiverze!rfn (Blocking)
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The SSH worm component ... Brute-force with embedded dictionary ... The embedded credential dictionary is predictable but effective: root, admin, password, 123456, 1234, master, raspberry, qwerty, portfolio, administrator
Prior public reporting on RedTail comes primarily from Akamai's 2024 research and two SANS Internet Storm Center diaries. Those reports described a capable but relatively straightforward cryptominer that exploited Log4j, PAN-OS, and ThinkPHP vulnerabilities to deploy XMRig.
The SSH worm component ... Brute-force with embedded dictionary ... The embedded credential dictionary is predictable but effective: root, admin, password, 123456, 1234, master, raspberry, qwerty, portfolio, administrator
Layer 3 -- SSH authorized_keys (remote access persistence): The attacker's SSH public key is written to authorized_keys files, providing key-based access
Layer 1 -- systemd (boot persistence): A systemd service unit with WantedBy=multi-user.target ensures the malware starts on every boot.
RedTail's binary includes CGo bindings to the complete PAM API ... It is a full PAM module that can intercept and override the authentication process itself. Once installed, the malware can accept a hardcoded password for any user account on the system.
The SSH worm component ... Brute-force with embedded dictionary ... The embedded credential dictionary is predictable but effective: root, admin, password, 123456, 1234, master, raspberry, qwerty, portfolio, administrator
Defense Evasion Software Packing T1027.002 UPX packing in later variants
After successful authentication, the binary deploys itself to the new target via SFTP, masquerading as sshd -- the legitimate SSH daemon process name.
First, the "clean" script -- a pre-deployment step that kills competing miners before RedTail installs itself.
RedTail's binary includes CGo bindings to the complete PAM API ... It is a full PAM module that can intercept and override the authentication process itself. Once installed, the malware can accept a hardcoded password for any user account on the system.
The SSH worm component ... Brute-force with embedded dictionary ... The embedded credential dictionary is predictable but effective
RedTail's binary includes CGo bindings to the complete PAM API ... It is a full PAM module that can intercept and override the authentication process itself. Once installed, the malware can accept a hardcoded password for any user account on the system.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux trojan used by TeamPCP that targets servers with exposed SSH services and serves as an automated attack vector in their shell-based operations.
A macOS malware detection associated with the native binary second-stage payload /Library/Caches/com.apple.act.mond delivered in the Axios npm supply-chain attack.
Mentioned only as a Defender alert title; no substantive connection to Zerobot is described.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.