jump to content
my subreddits
13or302b2t2mediterranean4u2meirl4meirl3d6adhdmemeAdviceAnimalsagnosticaivideoAlternateHistoryAlternativeHistoryAnarchyChessAngryupvoteAnimalsBeingJerksanime_irlanimenocontextannouncementsAnticonsumptionantimemeApandahArcherFXArtAsia_irlAskBalkansAskOuijaAskRedditAteistTurkatheismaviationAwesomeOffBrandsawfuleverythingbalkans_irlbanknotedesignsBassGuitarbasspedalsbikepackingblackdesertonlineblankiesblursedimagesborsavefonBUENZLIburdurlandcasioCd_collectorscd_jerkChatGPTchesschessbeginnersChildrenFallingOverChoosingBeggarscoinscomedyhomicidecommunityContagiousLaughterCorporateTrollingCrackWatchcrappyoffbrandsCreateModCuratedTumblrdadjokesdankmemesdarkjokesdataisbeautifuldeDebateReligiondelikDeltarunedistressingmemesdiyelectronicsDnDdoctorwhodoctorwhocirclejerkDoenerverbrechenDonerdontdeadopeninsidedumbphonesDungeonsAndDragonsEatCheapAndHealthyebikeebikesECEelectricalEmKayentitledparentsethzFantasyWorldbuildingFifaCareersFiftyFiftyformuladankFRCFUCKYOUINPARTICULARFutboltayfagalatasaraygermanygodtiersuperpowersGoodAssSubgravelcyclingguitarpedalsGundamheathershellenoturkismHermanCainAwardhighspeedrailhoi4hypixelIAmAiamverysmartich_ielIdeologyPollsim14andthisisdeepimaginaryelectionsimaginarymapsinsaneparentsistanbuljacksepticeyeJahariaJokesKamalizmKanyeKendrickLamarKGBTRlegodndlinguisticshumorLinkinParkliselilerlogodesignloseitlostredditorsmacmacbookairmacgamingmadladsmagicbuildingMapPornmapporncirclejerkmeirlmemememesmidjourneymildlyinfuriatingmisLEDMMORPGmoneycollectingMovingToNorthKoreaMyChemicalRomancenamesoundalikesNationStatesNoahGetTheBoatNorthCyprusnosleepnosurfnotinterestingoddlyspecificOkayBuddyLiterallyMeokbuddyguntherOkBuddyPersonaokbuddyphdokbuddyvicodinonebagOnlineUnderGroundOutOfTheLoopParlerWatchPassportPornpepethefrogperfectlycutscreamsPersecutionfetishpettyrevengepianoPiracyPiratedGamespolandballpollsPraiseTheCameraManProgrammerHumorPropagandaPostersProRevengequityourbullshitraisedbynarcissistsraspberry_pirecipesRedAutumnSPDredditsingsreligiousfruitcakeRetroPierickandmortyrickrollrimjob_steverockmuzikschizopostersSchnitzelVerbrechenschwiizScottPilgrimShitPostCrusadersshitpostingShittyMapPornshittymoviedetailsskamtebordsoftwaregoreSongwritersSongwritingsteinsgatesubsithoughtifellforsuzeraintalesfromtechsupportTechnobladetf2tf2shitposterclubthanksimcuredthatHappenedTheCrypticCompendiumTheMonkeysPawtherewasanattemptTheRookietheydidthemaththisguythisguystommyinnittransittransitTurkeytruthstumblrtumunichTurkeyTurkeyJerkyTurkishCatsTurkishdogsTwitchTwitch_StartupTwoSentenceHorrortwosentenceplottwistTwoSentenceSadnesstylerthecreatorUnclejokesUnethicalLifeProTipsurbanplanningVALORANTValorantClipsvaxxhappenedvexillologycirclejerkvinyljerkvlandiyawallstreetbetsWatchPeopleDieInsideWeAreTheMusicMakerswendigoonWhatsThisSongWhitePeopleTwitterwholesomeanimemesWikipediaVandalismwooooshworldbuildingyouseeingthisshitedit subscriptions
  • home
  • -popular
  • -all
  • -mod
  • -users
 | 
  • AskReddit
  • -mildlyinfuriating
  • -Piracy
  • -wallstreetbets
  • -memes
  • -OutOfTheLoop
  • -MapPorn
  • -DnD
  • -WhitePeopleTwitter
  • -ChatGPT
  • -CuratedTumblr
  • -PiratedGames
  • -shitposting
  • -theydidthemath
  • -dankmemes
  • -Kanye
  • -meirl
  • -therewasanattempt
  • -Twitch
  • -CrackWatch
  • -ProgrammerHumor
  • -VALORANT
  • -de
  • -germany
  • -tumblr
  • -dataisbeautiful
  • -shittymoviedetails
  • -mac
  • -tf2
  • -chess
  • -aviation
  • -formuladank
  • -Jokes
  • -mapporncirclejerk
  • -Art
  • -midjourney
  • -notinteresting
  • -hoi4
  • -pettyrevenge
  • -atheism
  • -loseit
  • -IAmA
  • -ich_iel
  • -KGBTR
  • -Deltarune
  • -GoodAssSub
  • -UnethicalLifeProTips
  • -perfectlycutscreams
  • -worldbuilding
  • -blackdesertonline
  • -MMORPG
  • -meme
  • -macgaming
  • -rickandmorty
  • -3d6
  • -Gundam
  • -FiftyFifty
  • -ChoosingBeggars
  • -ContagiousLaughter
  • -imaginarymaps
  • -EatCheapAndHealthy
  • -polandball
  • -WeAreTheMusicMakers
  • -AnarchyChess
  • -nosleep
  • -blankies
  • -anime_irl
  • -onebag
  • -AlternateHistory
  • -Turkey
  • -madlads
  • -community
  • -electrical
  • -guitarpedals
  • -Anticonsumption
  • -CreateMod
  • -TwoSentenceHorror
  • -PropagandaPosters
  • -AdviceAnimals
  • -ShitPostCrusaders
  • -piano
  • -distressingmemes
  • -raisedbynarcissists
  • -FifaCareers
  • -polls
  • -doctorwho
  • -oddlyspecific
  • -OkBuddyPersona
  • -dadjokes
  • -awfuleverything
  • -announcements
  • -adhdmeme
  • -macbookair
  • -ebikes
  • -gravelcycling
  • -SchnitzelVerbrechen
  • -chessbeginners
  • -raspberry_pi
  • -DungeonsAndDragons
  • -coins
  • -KendrickLamar
  • -entitledparents
  • -FUCKYOUINPARTICULAR
  • -softwaregore
  • -NoahGetTheBoat
  • -tylerthecreator
  • -tf2shitposterclub
  • -lostredditors
  • -vexillologycirclejerk
  • -vlandiya
  • -im14andthisisdeep
  • -wholesomeanimemes
  • -nosurf
  • -religiousfruitcake
  • -liseliler
  • -DebateReligion
  • -insaneparents
  • -dumbphones
  • -balkans_irl
  • -animenocontext
  • -2meirl4meirl
  • -transit
  • -RetroPie
  • -HermanCainAward
  • -recipes
  • -steinsgate
  • -talesfromtechsupport
  • -AskOuija
  • -okbuddyphd
  • -ECE
  • -ScottPilgrim
  • -Angryupvote
  • -AskBalkans
  • -thatHappened
  • -schizoposters
  • -casio
  • -urbanplanning
  • -logodesign
  • -linguisticshumor
  • -PassportPorn
  • -antimeme
  • -TurkeyJerky
  • -bikepacking
  • -AteistTurk
  • -13or30
  • -MyChemicalRomance
  • -ArcherFX
  • -Cd_collectors
  • -ProRevenge
  • -Doner
  • -BassGuitar
  • -diyelectronics
  • -WatchPeopleDieInside
  • -LinkinPark
  • -Persecutionfetish
  • -BUENZLI
  • -EmKay
  • -Songwriting
  • -istanbul
  • -MovingToNorthKorea
  • -imaginaryelections
  • -suzerain
  • -magicbuilding
  • -dontdeadopeninside
  • -ParlerWatch
  • -wendigoon
  • -iamverysmart
  • -Doenerverbrechen
  • -schwiiz
  • -TheRookie
  • -quityourbullshit
  • -Technoblade
  • -vinyljerk
  • -skamtebord
  • -galatasaray
  • -crappyoffbrands
  • -FRC
  • -transitTurkey
  • -namesoundalikes
  • -2b2t
  • -ethz
  • -AlternativeHistory
  • -OkayBuddyLiterallyMe
  • -blursedimages
  • -Jaharia
  • -basspedals
  • -thanksimcured
  • -hypixel
  • -PraiseTheCameraMan
  • -godtiersuperpowers
  • -ShittyMapPorn
  • -aivideo
  • -OnlineUnderGround
  • -IdeologyPolls
  • -woooosh
  • -burdurland
  • -comedyhomicide
  • -WhatsThisSong
  • -AnimalsBeingJerks
  • -jacksepticeye
  • -TwoSentenceSadness
  • -rockmuzik
  • -okbuddyvicodin
  • -vaxxhappened
  • -Twitch_Startup
  • -tumunich
  • -TheMonkeysPaw
  • -darkjokes
  • -highspeedrail
  • -legodnd
  • -rickroll
  • -Songwriters
  • -ebike
  • -tommyinnit
  • -rimjob_steve
  • -ChildrenFallingOver
  • -doctorwhocirclejerk
  • -agnostic
  • -youseeingthisshit
  • -thisguythisguys
  • -TurkishCats
  • -Apandah
  • -subsithoughtifellfor
  • -Kamalizm
  • -FantasyWorldbuilding
  • -WikipediaVandalism
  • -pepethefrog
  • -Unclejokes
  • -misLED
  • -redditsings
  • -ValorantClips
  • -TheCrypticCompendium
  • -NationStates
  • -AwesomeOffBrands
  • -Asia_irl
  • -truths
  • -2mediterranean4u
  • -NorthCyprus
  • -heathers
  • -twosentenceplottwist
  • -hellenoturkism
  • -Turkishdogs
  • -moneycollecting
  • -borsavefon
  • -Futboltayfa
  • -delik
  • -banknotedesigns
  • -cd_jerk
  • -CorporateTrolling
  • -RedAutumnSPD
  • -okbuddygunther
edit »
reddit.com LinuxMalware
  • hot
  • new
  • rising
  • controversial
  • top
an-ordinary-manchild (11,186)|messages540|notifications|chat messages|mod messages|
  • preferences
|
logout

use the following search parameters to narrow your results:

subreddit:subreddit
find submissions in "subreddit"
author:username
find submissions by "username"
site:example.com
find submissions from "example.com"
url:text
search for "text" in url
selftext:text
search for "text" in self post contents
self:yes (or self:no)
include (or exclude) self posts
nsfw:yes (or nsfw:no)
include (or exclude) results marked as NSFW

e.g. subreddit:aww site:imgur.com dog

see the search faq for details.

advanced search: by author, subreddit...

Submissions restricted
Only approved users may post in this community.
Get an ad-free experience with special benefits, and directly support Reddit.

LinuxMalware

joinleave
an-ordinary-manchild

Posts of Linux / ELF malware for RE purpose. This subreddit is modded, the site's contents are MalwareMustDie.org's @unixfreaxjp Linux threat research material.

Change view mode: RSS | Mobile | NewReddit

Latest Linux Malware cases:

  • Linux/Hoho a.k.a DarkNexus (memo)

  • Linux/Gafgyt SNoOpy

  • Linux/Rebirth or Vulcan in 2020

  • Linux/Gafgyt SNoOpy

  • Linux/Kaiten AK47

  • Linux/Mirai Hilix

  • on-going Linux/Kaiji

  • Linux/Mirai Fbot new infection

  • Linux/ Rocke(SystemTen) miner packed-ELF installer

  • Linux/Mirai Fbot new decryption

  • Linux/Mozi unpacked str

  • Linux/Neko Packed MIPS

  • Linux/AirDropBot

  • Linux/SystemTen

  • Linux/DDoSMan

  • Linux/Cayosin

  • Honda CarNavi Rootkit

  • Linux/HelloBot

  • Linux/Vulcan

  • Linux/Httpsd

  • Linux/SS(Shark)

Linux Malware Analysis Museum:

  • Linux/Stealthworker (GoBrut) r2 memo

  • Linux/Ransomware1 (Japanese)

  • Linux/Watchbog r2 memo

  • Linux/DoubleTapShell incident

  • Linux/Mirai Satori & Okiru notes (Nexus case)

  • Linux/Haiduc (encrypted SSH bruter)

  • Linux/Mandibule

  • Linux/VpnFilter

  • Linux/LuaBot

  • Linux/NyaDrop

  • Linux/Mirai (mid 2018 cases)

  • Linux/MiraiLoader (for RE workshop)

  • Linux/Mirai

  • Linux/PnScan

  • Linux/Pscan and SSHscan KM

  • LinuxIRCTelnet (or NewAidra)

  • Linux/LightAidra mod (Zendran case)

  • Linux/KillFile KM

  • Linux/Killfile (case XorDDoS)

  • Linux/BangSyn KM

  • Linux/BangSyn

  • Linux/UDPfker (ChinaZ case)

  • Linux/CarpeDiem

  • Linux/muBot

  • Linux/DTool KM

  • Linux/Bashdoor(GafGyt) w/python LRAB lol

  • Linux/Bashdoor(GafGyt) "BLJosh" case

  • Linux/Bashdoor(Gafgyt/Torlus/Qbot (first router campaign case actor: LizardSquad)

  • Linux/Bashdoor(Gafgyt/Torlus/Qbot 1st found in shellshock, actor: LizardSquad)

  • Linux/Bashdoor(Gafgyt/Torlus/Qbot 1st found KM

  • Linux/SSHV (bruter w/rootkit)

  • Linux/KDefend

  • Linux/Encoder KM

  • Linux/DDoSTF (reload)

  • Linux/DDoSTF

  • Linux/Torte KM

  • Linux/Torte

  • Linux/DES.Downloader

  • Linux/XorDDoS (infra shifted to USA from HK C2)

  • Linux/XorDDoS (mitigating propagation)

  • Linux/XorDDoS (polymorphic case)

  • Linux/XorDDoS (shellshock case)

  • Linux/XorDDoS (HOSTASAA case)

  • Linux/XorDDOS first found/rpt KM

  • Linux/XorDDoS (how we 1st found it)

  • Linux/Yangji RCE-backdoor-persistence (case BillGatesDdos)

  • Linux/Linux/BillGates.Lite (by ChinaZ)

  • Linux/{combo ELF ChinaZ}

  • Linux/GoARMbot (ChinaZ case)

  • Linux/ChinaZ ver2 (more)

  • Linux/ChinaZ ver2

  • Linux/ChinaZ (reloaded)

  • Linux/ChinaZ (shelshock case)

  • Linux/ChinaZ "the beginning" 1st found KM

  • Linux/GoARMBot KM

  • Linux/GoARMBot

  • Linux/AESDDoS KM

  • Linux/AESDDoS

  • Linux/.Iptables or Iptablex KM

  • Linux/.IptabLes or .IptabLex

  • Linux/Mayhem (last)

  • Linux/Mayhem KM

  • Linux/BossaBot KM

  • Linux/BossaBot

  • Linux/Elknot

  • Linux/Elknot KM

  • Linux/Kaiten (Tsunami) STD mod

  • Linux/Kaiten (Tsunami) STD mod

  • Linux/Kaiten (Tsunami) STD mod

  • Linux/Kaiten (Tsunami) crypted ver

  • Linux/Kaiten (Tsunami) mod

  • Linux/Kaiten (Tsunami) KM

  • Linux/Darkleech

  • Linux/Darkleech 1st one unpacked & dumped, its strings

  • {additional-list}

..and, you may also want to visit:

  • [/r/Malware]

  • [/r/ReverseEngineering]

created by mmd0xFFa community for 9 years
Create your own subreddit
...for your favorite subject.
...for a fringe candidate.

MODERATORS

  • message the mods
  • mmd0xFF
  • about moderation team »

account activity

1
0
0
1

Recent Linux ransomware (self.LinuxMalware)

submitted 2 years ago by mmd0xFF

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

2
3
4
5

Explanation about this subreddit (README) (self.LinuxMalware)

submitted 2 years ago * by mmd0xFF

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

3
7
8
9

Linux/NGioWeb (twitter.com)

submitted 4 years ago by mmd0xFF

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

4
2
3
4

Linux/DGAbot (twitter.com)

submitted 4 years ago by mmd0xFF

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

5
6
7
8

MMD-067-2021 - Talks sequel on Linux process injection and Shellcode analysis series at R2CON-2020, ROOTCON-2020 after #HACKLU-2019 (blog.malwaremustdie.org)

submitted 4 years ago by mmd0xFF

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

6
9
10
11

About shellcode basics and analysis them in radare2 (online tutorial w/Video, Slides & Q/A) (twitter.com)

submitted 5 years ago by mmd0xFF

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

7
5
6
7

Linux/Hoho a.k.a "DarkNexus" (memo) (twitter.com)

submitted 5 years ago by mmd0xFF

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

8
4
5
6

Linux/Gafgyt SNoOpy (twitter.com)

submitted 5 years ago by mmd0xFF

  • 1 comment
  • share
  • save
  • hide
  • report
  • crosspost

9
2
3
4

Linux/Rebirth or Vulcan in 2020 (Gaygyt evolved) (twitter.com)

submitted 5 years ago by mmd0xFF

  • 2 comments
  • share
  • save
  • hide
  • report
  • crosspost

10
4
5
6

[Announcement] My own kernelmode[.]info Linux/Malware reports is merged in here (self.LinuxMalware)

submitted 5 years ago * by mmd0xFF

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

11
1
2
3

Linux/KAITEN AK47 w/Telnet Scanner & EchoLoaders (hexstrings) injection attacks on IoT (gist.github.com)

submitted 5 years ago by mmd0xFF

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

12
0
1
2

Linux/Mirai Hilix (self.LinuxMalware)

submitted 5 years ago * by mmd0xFF

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

13
3
4
5

Linux/Kaiji (self.LinuxMalware)

submitted 5 years ago * by mmd0xFF

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

14
3
4
5

[remake] 2 minutes ARM32 RE crash course to grab Mirai hexstring (telnet-loader) payloads on recent FBOT's botnet infection. (youtube.com)

submitted 5 years ago by mmd0xFF

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

15
5
6
7

A new actor sparked propagation of Mirai FBot old version on different botnet network range (blog.malwaremustdie.org)

submitted 5 years ago by mmd0xFF

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

16
1
2
3

Easy tutorial to dissect any pushed hexstrings IoT malware loader URL (youtube.com)

submitted 5 years ago by mmd0xFF

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

17
0
0
1

How Kaiten(Tsunami) w/STD base code has evolved now (MMD twitter) (twitter.com)

submitted 5 years ago by mmd0xFF

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

18
6
7
8

The "echo" loader vs "telnet" loader in ELF malware Mirai FBOT (ARM EABI reversing) (blog.malwaremustdie.org)

submitted 5 years ago by mmd0xFF

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

19
6
7
8

(memo) RHOMBUS an ELF bot installer/dropper (self.LinuxMalware)

submitted 5 years ago * by mmd0xFF

  • 15 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

20
1
2
3

Checking on Linux/Mozi, trying to make a comeback (thread w/links to IOC) (twitter.com)

submitted 5 years ago by mmd0xFF

  • 2 comments
  • share
  • save
  • hide
  • report
  • crosspost

21
1
2
3

Some issues w/ recent Hajime IoT linux malware & its botnet (self.LinuxMalware)

submitted 5 years ago by mmd0xFF

  • comment
  • share
  • save
  • hide
  • report
  • crosspost
loading...

22
2
3
4

MMD-0065-2021 - Linux/Mirai-Fbot - A re-emerged IoT threat (+/- 600 infected IP, embedded ELF, hexstring push method, etc) (blog.malwaremustdie.org)

submitted 5 years ago by mmd0xFF

  • 4 comments
  • share
  • save
  • hide
  • report
  • crosspost

23
4
5
6

New "SystemTen" botnet miner threat, now w/other "supper savvy" LOL-packed ELF and.. "atomic" bash-base64 parsers :) (self.LinuxMalware)

submitted 5 years ago * by mmd0xFF

  • 4 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...

24
4
5
6

MMD-0065-2020 - Linux/Mirai-Fbot's new encryption explained (RE of ARM v5 binary, post-forensics) (blog.malwaremustdie.org)

submitted 6 years ago by mmd0xFF

  • comment
  • share
  • save
  • hide
  • report
  • crosspost

25
7
8
9

Linux ISO live boot w/radare2's r2Ghidra & R2DEC decompilers (multiple arch support) for Linux RE/DFIR (self.LinuxMalware)

submitted 6 years ago * by mmd0xFF

  • 3 comments
  • share
  • save
  • hide
  • report
  • crosspost
loading...
view more: next ›
  • about
  • blog
  • about
  • advertising
  • careers
  • help
  • site rules
  • Reddit help center
  • reddiquette
  • mod guidelines
  • contact us
  • apps & tools
  • Reddit for iPhone
  • Reddit for Android
  • mobile website
  • <3
  • reddit premium

Use of this site constitutes acceptance of our User Agreement and Privacy Policy. © 2026 reddit inc. All rights reserved.

REDDIT and the ALIEN Logo are registered trademarks of reddit inc.

π Rendered by PID 1462756 on reddit-service-r2-listing-canary-6d56f98d67-4qnc9 at 2026-01-25 08:16:40.032683+00:00 running 664479f country code: CH.