ClientKing is a Rust-based Linux and router implant associated with the China-linked threat actor Jewelbug, also tracked as Earth Alux, REF7707, Ink Dragon, and CL-STA-0049. It is used in espionage-oriented intrusions to extend access beyond Windows endpoints and browsers into Linux servers, network infrastructure, and router-class devices, including ARM64 systems and ASUS routers.
ClientKing functions as a backdoor that provides remote command execution through an interactive shell, supports SOCKS-based pivoting, and offers multiple command-and-control transports, including DNS tunneling. Reported builds support five distinct C2 channels, indicating an emphasis on operational resilience and covert communications in restricted environments. The implant can also load kernel modules directly from memory, enabling deeper post-compromise access and facilitating deployment of companion tooling at the kernel level.
ClientKing has been observed as part of a broader Jewelbug malware ecosystem that also includes the Antino Windows backdoor and browser-based tooling managed through the XG-Web framework. Within that ecosystem, ClientKing is used to reach servers and network devices after initial compromise, helping operators move from user-facing systems into internal infrastructure. Related Linux tooling tied to the same operations has included a kernel-module rootkit and a malicious authentication module designed to intercept credentials from privileged authentication workflows.
Observed targeting linked to ClientKing includes government, military, and telecommunications environments across the Middle East, Southeast Asia, and South Asia, as well as enterprise infrastructure. Its feature set and deployment context are consistent with long-term covert access, internal pivoting, and support for broader espionage operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ClientKing, a Rust implant that targets Linux servers and routers, and uses five C&C channels, including a DNS tunnel, to facilitate interactive shell, SOCKS pivoting, and the ability to load kernel modules directly from memory.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The researchers explained that the threat actor obtained write access to the webmail installation used by multiple government ministries and agencies after compromising a shared web-hosting platform operated by the state telecommunications provider and national services agency.
"Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing framework that turns a victim's browser into a full remote-control channel..."
Finally, the group also abused Google Docs for payload delivery and C2. When operators launched a campaign, the backend created public Google documents containing obfuscated payloads, which implants would retrieve and execute.
"ClientKing, a Rust implant that targets Linux servers and routers, and uses five C&C channels, including a DNS tunnel..."
"The group's separate Linux and router implant enables it to extend its reach into network infrastructure, with a couple of builds configured to beacon through the internal corporate proxy..."
"ClientKing... uses five C&C channels, including a DNS tunnel, to facilitate interactive shell, SOCKS pivoting..."
The hackers used public Google Docs to host obfuscated payloads retrieved and executed by their implants, helping the malicious traffic blend in with legitimate Google services.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Rust-based implant for Linux servers and routers that supports multiple C2 channels, DNS tunneling, interactive shell access, SOCKS pivoting, and in-memory kernel module loading.
A Linux and router implant that supports multiple C2 methods including DNS tunnelling, and provides remote shell access and pivoting capabilities.
A custom Linux backdoor used by Jewelbug as one of its primary malware implants.
A Rust-based implant targeting Linux servers, ARM64 devices, and ASUS routers, supporting command execution, SOCKS proxying, DNS tunneling, and in-memory kernel module loading.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.