BridgeAgent is a Linux backdoor used by the China-nexus cyberespionage actor Fire Ant to maintain access to compromised hosts. It masquerades as a legitimate Zabbix monitoring agent, disguises its running process as a desktop component, and persists through a systemd service running with root privileges. BridgeAgent stores encrypted configuration data and communicates with attacker-controlled infrastructure over TLS. It supports remote command execution, TLS reverse shells, and execution of additional payloads. It has been deployed on a Linux host connected to compromised network infrastructure through a covert GRE tunnel, within operations targeting network-management infrastructure and using compromised systems as staging points to investigate connected high-value environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Истражувачите исто така откриле претходно недокументирана задна врата (backdoor) наречена „BridgeAgent“, која Fire Ant ја маскирал како легитимен Zabbix агент за мониторинг.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
TacTap... wrote collected credential material to an obfuscated log artifact... /var/log/.tacplus.acct [was an] XOR-obfuscated TACACS credential artifact.
BridgeAgent... polled the attacker's infrastructure over TLS on port 443 for commands and reverse-shell instructions.
Бэкдор BridgeAgent ... поддерживал ... загрузку дополнительных пейлоадов.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux backdoor disguised as a Zabbix monitoring agent. It establishes root-level systemd persistence, masquerades its process as /usr/bin/gnome-shell, communicates over TLS on port 443, and supports command execution, payload download, and reverse shells.
Previously undocumented backdoor deployed by Fire Ant and disguised as a legitimate Zabbix monitoring agent. It persists as a systemd service with root privileges, supports TLS reverse-shell connections, and executes additional payloads on compromised hosts.
Linux backdoor masquerading as a monitoring agent. It stores encrypted configuration in /opt/.ICEauthority, communicates with external infrastructure over TLS, and serves as a staging point for scanning and access through the covert GRE tunnel.
A previously undocumented Linux backdoor masquerading as a Zabbix monitoring agent. It persists through a root-level systemd service, provides TLS reverse-shell access, and can execute additional payloads on compromised hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.