[kwlug-disc] Fw: Backdoor found in widely used Linux utility

Khalid Baheyeldin kb at 2bits.com
Sun Mar 31 12:12:41 EDT 2024

Here is a very readable detailed breakdown of how obfuscated shell
scripting was used in this exploit.

Very clever, very opaque, and effective.

The committer of these files took a few years to lay the groundwork
for his exploit (2021 to 2024, most likely by gaining trust first).

One tends to think this is funded by (or will be sold to) a state
actor or organized crime ...


More information about the kwlug-disc mailing list