Also known as: Fysbis
Executive Summary
Fysbis is a Linux backdoor employed by APT28 since at least 2014. It provides remote command execution, stealthy C2 communication over HTTP/HTTPS, data exfiltration and lateral movement capabilities. Immediate detection, isolation and deep analysis are essential to contain potential compromise.
Enhanced Description
Fysbis is a Linux‑specific backdoor that has been identified in activity attributed to the Russian state-sponsored threat group APT28, also known as Fancy Bear. The malware was first documented by Palo Alto Networks in a 2014 analysis and has since appeared in subsequent APT28 toolkits. It is designed to establish persistent remote access to compromised Linux hosts, enabling adversaries to issue commands, exfiltrate data, and pivot to other systems within the network. At its core, Fysbis communicates with a command-and-control (C&C) infrastructure over encrypted channels, typically HTTP/HTTPS, disguising traffic as legitimate web requests. Once loaded onto a victim machine it can execute arbitrary shell commands, gather system information, harvest credentials, and maintain persistence through daemonization or modifying startup scripts. The backdoor also supports privilege escalation techniques common to APT28 toolkits, thereby allowing attackers to move laterally and expand their foothold. Because Fysbis operates on Linux platforms that are often used in research, industrial control systems, and government environments, the potential impact includes data compromise, intellectual property theft, and disruption of mission‑critical services. Operators should treat any detected instance as a high‑severity incident requiring immediate containment and forensic investigation.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The information available for Fysbis is limited primarily to a single early report from Palo Alto Networks. Consequently, confidence in the finer details of its behavior is moderate; certain capabilities such as privilege escalation methods or persistence mechanisms are inferred based on typical APT28 patterns rather than direct evidence. Key gaps include lack of publicly released malware samples, detailed code analysis, and comprehensive attribution records beyond the initial 2014 citation.
Fysbis is a Linux-based backdoor used by APT28 that dates back to at least 2014.(Citation: Fysbis Palo Alto Analysis)