Saturday, 23 August

Saturday, 23 August2025

Linux Malware Evades Detection by Hiding Code in RAR Filenames, Delivers VShell Backdoor

Linux Malware Evades Detection by Hiding Code in RAR Filenames, Delivers VShell Backdoor
A new Linux-specific attack sends phishing emails with RAR attachments containing maliciously crafted filenames that embed Base64-encoded Bash commands. When a shell script lists these filenames, the code executesbypassing antivirus tools that dont inspect filenames. The embedded payload then downloads an ELF binary tailored to the systems architecture, installs the VShell backdoor, and connects to a C2 server for encrypted control. This stealthy method exploits shell parsing flaws.
Read full story at The Hacker News

Subscribe To Our Newsletter.

Full Name
Email