Last seven days
- First activity
- Sep 16, 2026
- Last activity
- Sep 18, 2026
- Feed role
- C2
- Host form
- 7 IP / 0 hostnames
BridgeAgent is a Linux backdoor associated with the China-nexus Fire Ant espionage activity, which has been assessed to overlap with UNC3886 activity.
Profile source: Mallory opens in a new tabBridgeAgent
BridgeAgent is a Linux backdoor associated with the China-nexus Fire Ant espionage activity, which has been assessed to overlap with UNC3886 activity. It masquerades as a legitimate Zabbix monitoring agent and establishes root-level persistence through a systemd service. BridgeAgent communicates with attacker-controlled infrastructure over TLS and supports remote command execution, deployment of additional payloads, and TLS-enabled reverse shells. It was deployed on Linux management or staging hosts connected to compromised network infrastructure, enabling durable remote access and post-compromise operations.
C2 tracking
Derp observations, rolling seven-day window
Samples
297952db6c409fd483df4dc22f741ea59eb55f551319ed6d50509068fdfb0df3 96c5fcd6e73a2fd78693a12f6794027ad53d7e00432c085e5e58e44abb131846 b0dd515bb7aa8f966469cc470ff9845d4b7bdcdb0ce25ea5ec9b9923dd183d65 a0490261a1fdd87a20e8b23ebafa98d24cbd4b82622ffe2009cada059388faae 50fdd8477244d8b3a59aa81bb2020ad2aad38d557039b36a38f6a8a74f87a969 4c0d2372f3d03a95fae67956989fbc9e307b318c5551f74a48c2b850d55bb169 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 e7b3c12ea05c6df9934ee5cac978c84ae927020621cccd24e19d28da0d3c911e e91b1af687dd6581d7558a22934d625f79d8587a04bd01b8450da3e0691c56c0 8a230e6bf97c16af33527a2d593e346d9ecb025c51ebdce163c60a4a7d952b18 Reported operators
Еще одной находкой исследователей стал Linux-бэкдор BridgeAgent, замаскированный под агент мониторинга Zabbix.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.