Old and new OpenSSH backdoors threaten Linux serversHelp Net Security·Dec 9, 18:30 UTC · Dec 9, 2018Malware42
OpenSSH now supports FIDO U2F security keys for 2The Hacker News·Feb 17, 17:18 UTC · Feb 17, 2020Malware30
OpenSSH Trojan Campaign Targets IoT and Linux SystemsInfosecurity Magazine·Jun 23, 17:00 UTC · Jun 23, 2023Malware42
Operation SkyCloak Deploys Tor-Enabled OpenSSH Backdoor Targeting Defense SectorsThe Hacker News·Nov 4, 10:49 UTC · Nov 4, 2025Malware55
Malware report for Q2 2024 — a quarterly reviewKaspersky Securelist·Sep 5, 07:45 UTC · Sep 5, 2024MalwareCVE-2024-309460
⚡ Weekly Recap: WhatsApp 0-Day, Docker Bug, Salesforce Breach, Fake CAPTCHAs, Spyware App & MoreThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2025Malware in the wildCVE-2025-55177CVE-2025-43300CVE-2025-907460
China-linked spies backdoored authentication stack to stay hidden for yearsHelp Net Security·Jun 15, 00:00 UTC · Jun 15, 2026Malware55
China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a DecadeThe Hacker News·Jun 12, 18:17 UTC · Jun 12, 2026MalwareCVE-2024-2039947
What we know about the xz Utils backdoor that almost infected the worldArs Technica · Security·Apr 1, 06:55 UTC · Apr 1, 2024Malware55
Wikileaks: BothanSpy and Gyrfalcon CIA Implants steal SSH Credentials from Windows and Linux OSsSecurity Affairs·Jul 6, 20:18 UTC · Jul 6, 2017Malware30
Kaspersky analysis of the backdoor in XZKaspersky Securelist·Apr 12, 08:00 UTC · Apr 12, 2024Malware42
Wikileaks Unveils CIA Implants that Steal SSH Credentials from Windows & Linux PCsThe Hacker News·Jul 6, 18:41 UTC · Jul 6, 2017Malware30
New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH CredentialsThe Hacker News·May 9, 06:23 UTC · May 9, 2026Malware42
⚡ Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & MoreThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2026Malware in the wildCVE-2026-3909CVE-2026-3910CVE-2026-3913+40 CVEs260
Bloody Wolf Targets Uzbekistan, Russia Using NetSupport RAT in SpearThe Hacker News·Feb 9, 10:58 UTC · Feb 9, 2026Malware42
ThreatsDay Bulletin: AI Tools in Malware, Botnets, GDI Flaws, Election Attacks & MoreThe Hacker News·Nov 7, 11:19 UTC · Nov 7, 2025MalwareCVE-2025-30388CVE-2025-53766CVE-2025-4798447
Trojanized ESET Installers Drop Kalambur Backdoor in Phishing Attacks on UkraineThe Hacker News·Nov 7, 06:24 UTC · Nov 7, 2025Malware in the wildCVE-2025-808860
Researchers Spot XZ Utils Backdoor in Dozens of Docker Hub Images, Fueling Supply Chain RisksThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2025MalwareCVE-2024-309460
Stealthy backdoor found hiding in SOHO devices running LinuxHelp Net Security·Jun 23, 00:00 UTC · Jun 23, 2025Malware55
UAC-0125 Abuses Cloudflare Workers to Distribute Malware Disguised as Army+ AppThe Hacker News·Dec 20, 04:17 UTC · Dec 20, 2024Malware42
FIN7 Cybercrime Group Targeting U.S. Auto Industry with Carbanak BackdoorThe Hacker News·Jul 17, 10:25 UTC · Jul 17, 2024Malware42
Ebury botnet compromises 400,000+ Linux serversHelp Net Security·May 16, 00:00 UTC · May 16, 2024Malware55
Ebury Botnet Malware Compromises 400,000 Linux Servers Over Past 14 YearsThe Hacker News·May 15, 00:00 UTC · May 15, 2024MalwareCVE-2021-4546747
Ebury Botnet Operators Diversify with Financial and Crypto TheftInfosecurity Magazine·May 14, 17:00 UTC · May 14, 2024Malware42
ToddyCat Hacker Group Uses Advanced Tools for IndustrialThe Hacker News·Apr 23, 05:39 UTC · Apr 23, 2024Malware42
XZ Utils backdoor update: Which Linux distros are affected and what can you do?Help Net Security·Apr 8, 13:26 UTC · Apr 8, 2024MalwareCVE-2024-309447
Urgent: Secret Backdoor Found in XZ Utils Library, Impacts Major Linux DistrosThe Hacker News·Apr 2, 04:39 UTC · Apr 2, 2024Malware in the wildCVE-2024-309460
Russia's APT28 used new malware in a recent phishing campaignSecurity Affairs·Dec 29, 14:59 UTC · Dec 29, 2023Malware42
StripedFly: Perennially flying under the radarKaspersky Securelist·Oct 26, 04:00 UTC · Oct 26, 2023Malware30
Lightning Framework, a previously undetected malware targets Linux systemsSecurity Affairs·Jul 21, 17:37 UTC · Jul 21, 2022Malware30
Symbiote: A Stealthy Linux Malware Targeting Latin American Financial SectorThe Hacker News·Jun 10, 14:39 UTC · Jun 10, 2022Malware42
TrickBot Malware Targeted Customers of 60 HighThe Hacker News·Feb 18, 03:20 UTC · Feb 18, 2022Malware30
Trickbot banking Trojan modules overviewKaspersky Securelist·Oct 19, 10:11 UTC · Oct 19, 2021Malware42
More Detail on the Juniper Hack and the NSA PRNG BackdoorSchneier on Security·Sep 9, 11:13 UTC · Sep 9, 2021Malware42
Signed MSI files, Raccoon and Amadey are used for installing ServHelper RATCisco Talos·Aug 12, 12:00 UTC · Aug 12, 2021Malware42