This actor’s toolset notably includes a cross-platform backdoor named DinodasRAT, also known as XDealer... In this blog post, we share our full technical analysis of the latest Linux version (v11) of DinodasRAT, which we track as Linodas.
DinodasRAT
DinodasRAT, also known as XDealer, is a cross-platform espionage backdoor associated with China-aligned intrusion activity.
DinodasRAT
Family profile
DinodasRAT, also known as XDealer, is a cross-platform espionage backdoor associated with China-aligned intrusion activity. It has been observed in operations linked to clusters aligned with Earth Krahang and has also been reported in activity attributed to LuoYu. The malware exists in both Windows and Linux branches, with the Linux variant commonly tracked as Linodas and used to target server environments including Ubuntu and Red Hat systems.
On Windows, DinodasRAT has been deployed in targeted spearphishing-led intrusions against government entities. Document-themed lures have been used to deliver an archive containing a malicious executable that installs the backdoor. Once active, the malware supports broad remote administration and surveillance functions, including screenshot capture, clipboard collection, file transfer, registry manipulation, process and service control, command execution, and interactive shell access. It encrypts command-and-control traffic using the Tiny Encryption Algorithm and can communicate over TCP, with support for UDP as an alternative.
On Linux, Linodas is a mature server-focused backdoor rather than a simple port of the Windows codebase. It establishes persistence using operating-system-appropriate startup mechanisms on Ubuntu and Red Hat families, daemonizes itself, stores configuration locally, and generates a unique victim identifier. It maintains encrypted communications with its controller and supports extensive remote operations including file management, process enumeration and termination, service control, command execution, reverse shell access, proxying, self-removal, and collection of logged-in user activity from standard Linux accounting sources.
A notable enhancement in later Linux versions is a companion filter component that replaces selected system binaries and suppresses output containing attacker-defined values, hiding malicious artifacts from common administrative utilities. This behavior gives the Linux branch rudimentary rootkit-like concealment capabilities in addition to persistence and full remote control.
DinodasRAT has been used for cyber espionage against governmental and regional targets and has been reported targeting Linux servers in multiple countries. Its development shows code reuse from publicly available remote administration projects, but its operational use, persistence mechanisms, encrypted communications, and concealment features make it a capable long-term access platform for state-aligned intrusion sets.
Capabilities
- Defense Evasion
- Exfiltration
- Persistence
- Post Exploitation
- Process Injection
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Reported operators
Threat actors
3 named in public reportingThis actor’s toolset notably includes a cross-platform backdoor named DinodasRAT, also known as XDealer... In this blog post, we share our full technical analysis of the latest Linux version (v11) of DinodasRAT, which we track as Linodas.
“China-linked groups deployed a Linux variant of DinodasRAT…”
MITRE ATT&CK