Skip to content

BridgeAgent

BridgeAgent is a Linux backdoor associated with the China-nexus Fire Ant espionage activity, which has been assessed to overlap with UNC3886 activity.

Profile source: Mallory opens in a new tab

BridgeAgent

Family profile

BridgeAgent is a Linux backdoor associated with the China-nexus Fire Ant espionage activity, which has been assessed to overlap with UNC3886 activity. It masquerades as a legitimate Zabbix monitoring agent and establishes root-level persistence through a systemd service. BridgeAgent communicates with attacker-controlled infrastructure over TLS and supports remote command execution, deployment of additional payloads, and TLS-enabled reverse shells. It was deployed on Linux management or staging hosts connected to compromised network infrastructure, enabling durable remote access and post-compromise operations.

Capabilities

  • Defense Evasion
  • Persistence
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 16, 2026
Last activity
Sep 18, 2026
Feed role
C2
Host form
7 IP / 0 hostnames

Leading locations

  • DE3
  • FI3
  • NL1

Leading providers

  • DEDIK SERVICES LIMITED2
  • Hetzner Online GmbH2
  • Local NCC Ltd.1
  • UP-NETWORK Sarl1
  • VPSPay ASN1

Infrastructure traits

  • Hosting 7

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
UNC3886

Еще одной находкой исследователей стал Linux-бэкдор BridgeAgent, замаскированный под агент мониторинга Zabbix.

MITRE ATT&CK

BridgeAgent in ATT&CK

11 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.