Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareUsed by 2 actors

Multiverze

Multiverze is described in the provided content as a Linux trojan used by the threat actor TeamPCP. It is characterized as an automated threat that primarily targets Linux servers exposing accessible SSH services, using SSH as its main attack vector to obtain shells on compromised systems. The content also shows Microsoft Defender for Endpoint detection coverage for a related macOS classification under Trojan:MacOS/Multiverze!rfn, indicating the name is used by defenders as malware nomenclature. High-confidence details in the provided material are limited to this characterization; no additional verified information on payload functionality, persistence, specific industries targeted, or indicators of compromise for Multiverze itself is directly provided beyond its association with TeamPCP and SSH-exposed Linux servers.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
TeamPCP

TeamPCP had made use of Multiverze — A Linux Trojan which is an automated threat that affects Linux servers running accessible SSH services as its main attack vector for Shells

via theravenfile blogtheravenfile.com
APT38

Microsoft Defender for Endpoint – Trojan:MacOS/Multiverze!rfn (Blocking)

via microsoft generalmicrosoft.com
MITRE ATT&CK

Techniques & procedures

19 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1078Valid AccountsEvidence1

The SSH worm component ... Brute-force with embedded dictionary ... The embedded credential dictionary is predictable but effective: root, admin, password, 123456, 1234, master, raspberry, qwerty, portfolio, administrator

T1190Exploit Public-Facing ApplicationEvidence1

Prior public reporting on RedTail comes primarily from Akamai's 2024 research and two SANS Internet Storm Center diaries. Those reports described a capable but relatively straightforward cryptominer that exploited Log4j, PAN-OS, and ThinkPHP vulnerabilities to deploy XMRig.

Execution

1 technique
T1059.004Unix ShellEvidence1

Bash dropper fires --> dlr() downloads arch-specific payload ... Six dropper script variants were recovered ... each following the same bash template.

Persistence

4 techniques
T1078Valid AccountsEvidence1

The SSH worm component ... Brute-force with embedded dictionary ... The embedded credential dictionary is predictable but effective: root, admin, password, 123456, 1234, master, raspberry, qwerty, portfolio, administrator

T1098.004SSH Authorized KeysEvidence1

Layer 3 -- SSH authorized_keys (remote access persistence): The attacker's SSH public key is written to authorized_keys files, providing key-based access

T1543.002Systemd ServiceEvidence1

Layer 1 -- systemd (boot persistence): A systemd service unit with WantedBy=multi-user.target ensures the malware starts on every boot.

T1556.003Pluggable Authentication ModulesEvidence1

RedTail's binary includes CGo bindings to the complete PAM API ... It is a full PAM module that can intercept and override the authentication process itself. Once installed, the malware can accept a hardcoded password for any user account on the system.

Privilege Escalation

3 techniques
T1078Valid AccountsEvidence1

The SSH worm component ... Brute-force with embedded dictionary ... The embedded credential dictionary is predictable but effective: root, admin, password, 123456, 1234, master, raspberry, qwerty, portfolio, administrator

T1098.004SSH Authorized KeysEvidence1

Layer 3 -- SSH authorized_keys (remote access persistence): The attacker's SSH public key is written to authorized_keys files, providing key-based access

T1543.002Systemd ServiceEvidence1

Layer 1 -- systemd (boot persistence): A systemd service unit with WantedBy=multi-user.target ensures the malware starts on every boot.

Stealth

5 techniques
T1027.002Software PackingEvidence1

Defense Evasion Software Packing T1027.002 UPX packing in later variants

T1036.005Match Legitimate Resource Name or LocationEvidence1

After successful authentication, the binary deploys itself to the new target via SFTP, masquerading as sshd -- the legitimate SSH daemon process name.

T1070.004File DeletionEvidence1

First, the "clean" script -- a pre-deployment step that kills competing miners before RedTail installs itself.

T1078Valid AccountsEvidence1

The SSH worm component ... Brute-force with embedded dictionary ... The embedded credential dictionary is predictable but effective: root, admin, password, 123456, 1234, master, raspberry, qwerty, portfolio, administrator

T1564.001Hidden Files and DirectoriesEvidence1

Rename the binary to .redtail (the leading dot hides it from ls )

Defense Impairment

1 technique
T1556.003Pluggable Authentication ModulesEvidence1

RedTail's binary includes CGo bindings to the complete PAM API ... It is a full PAM module that can intercept and override the authentication process itself. Once installed, the malware can accept a hardcoded password for any user account on the system.

Credential Access

2 techniques
T1110.003Password SprayingEvidence1

The SSH worm component ... Brute-force with embedded dictionary ... The embedded credential dictionary is predictable but effective

T1556.003Pluggable Authentication ModulesEvidence1

RedTail's binary includes CGo bindings to the complete PAM API ... It is a full PAM module that can intercept and override the authentication process itself. Once installed, the malware can accept a hardcoded password for any user account on the system.

Discovery

2 techniques
T1082System Information DiscoveryEvidence1

Detect CPU architecture via uname -mp

T1083File and Directory DiscoveryEvidence1

Search for a writable directory that is not mounted with noexec ... Later variants parse /proc/mounts directly to identify candidate directories.

Lateral Movement

2 techniques
T1021.004SSHEvidence1

The binary embeds a full SSH client library ... and uses it for automated lateral movement.

T1570Lateral Tool TransferEvidence1

After successful authentication, the binary deploys itself to the new target via SFTP, masquerading as sshd

Collection

1 technique
T1005Data from Local SystemEvidence1

Collection Data from Local System T1005 SSH key harvesting ( known_hosts , id_rsa )

Command and Control

2 techniques
T1071.001Web ProtocolsEvidence1

The C2 channel itself uses HTTP/2 over TLS, making traffic analysis difficult

T1573Encrypted ChannelEvidence1

C2 communications are encrypted with ChaCha20-Poly1305, an authenticated encryption scheme.

Impact

1 technique
T1496Resource HijackingEvidence1

Impact Resource Hijacking T1496 XMRig (CPU) + NBminer (GPU) mining

INDICATORS OF COMPROMISE

IOCs tracked for this family

22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
4 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
13 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
5 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in app4 months ago
hash.md5●●●●●●●●●●●●View more in app4 months ago
hash.sha1●●●●●●●●●●●●View more in app4 months ago
hash.sha256●●●●●●●●●●●●View more in app4 months ago
hash.sha256●●●●●●●●●●●●View more in app4 months ago
hash.sha256●●●●●●●●●●●●View more in app4 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching22

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping19

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.