Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

AI-Driven Tools Uncover GhostPenguin Backdoor Attacking Linux Servers

A newly identified Linux backdoor, named GhostPenguin, has been detected by Trend Micro Research. The malware remained undetected for over four months following its initial submission to VirusTotal in July 2025.

A newly identified Linux backdoor, named GhostPenguin, has been detected by Trend Micro Research. The malware remained undetected for over four months following its initial submission to VirusTotal in July 2025.

GhostPenguin is a sophisticated backdoor developed in C++ that offers remote access and file system manipulation capabilities. It communicates with command-and-control servers using an RC5-encrypted UDP channel through port 53. The malware exhibits advanced session handshake processes and uses multi-threading for critical operations such as registration, heartbeat signaling, and command execution.

Upon execution, GhostPenguin collects extensive system information and transmits it to its command-and-control server. The malware supports various commands, including spawning remote shells and performing comprehensive file and directory operations. It ensures reliable communication over UDP by implementing a custom reliability layer.

Analysis indicates that GhostPenguin is still under active development, evidenced by debug artifacts and unused persistence functions within its code. The malware iterates through a global configuration of C&C server addresses, and leftover debug configurations suggest it is not yet a mature threat.

A newly identified Linux backdoor, named GhostPenguin, has been detected by Trend Micro Research.
Benjamin Scott · Thehackingpost

Trend Micro Research employed an AI-driven, automated threat hunting pipeline to identify GhostPenguin. This method involved extracting artifacts from numerous malware samples, generating structured profiles, and using custom YARA rules combined with VirusTotal queries. These artifacts were stored for comprehensive analysis to develop effective hunting rules for zero-detection samples.

The discovery of GhostPenguin underscores the importance of AI-automated threat hunting in identifying advanced, stealthy malware. The Trend Vision One platform now detects and blocks indicators of compromise associated with GhostPenguin, providing customers with threat insights and intelligence reports.

Advertisement

The ongoing development of GhostPenguin highlights significant risks to Linux server infrastructures across enterprise environments.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories