Malware & Threats

New ‘Auto-Color’ Linux Malware Targets North America, Asia

New Linux malware named Auto-Color, which allows full remote access to compromised devices, targets North America and Asia.

Linux malware

Palo Alto Networks has shared details on a new piece of Linux malware that gives threat actors backdoor access to compromised devices. 

Named Auto-Color (based on the name of the initial payload), the Linux malware was first spotted by the security firm in early November 2024. Palo Alto obtained the most recent sample on December 5, 2024. 

The company’s analysis showed that Auto-Color has mainly been used to target universities and governments in North America and Asia. 

Palo Alto has not been able to determine how the malware reaches targets, but pointed out that it needs to be explicitly executed by the victim on a Linux computer.

Once it has been fully deployed on a system, it provides its operator with complete remote access to the targeted machine, and it’s “very difficult to remove without specialized software”, the security firm said.

The malware supports commands that enable the attacker to collect host information, uninstall the malware, create a reverse shell, create and modify files, execute a program, and turn the device into a proxy.

Advertisement. Scroll to continue reading.

Auto-Color uses various methods to evade detection, including using harmless-looking file names, hiding C&C connections using a sophisticated technique, and leveraging proprietary encryption algorithms to protect information pertaining to communication and configuration.

Palo Alto has shared indicators of compromise (IoCs) to help defenders detect the Auto-Color Linux malware on their networks.

Related: Golang Backdoor Abuses Telegram for C&C Communication

Related: Chinese Botnet Powered by 130,000 Devices Targets Microsoft 365 Accounts

Related: Chinese APT Tools Found in Ransomware Schemes, Blurring Attribution Lines

Related: New FrigidStealer macOS Malware Distributed as Fake Browser Update

Related Content

Malware & Threats

US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.

Malware & Threats

Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware.

Malware & Threats

The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.

Cybercrime

The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash.

Artificial Intelligence

The AI giant is logging customers out of their accounts and removing payment data to prevent unauthorized Claude usage.

Artificial Intelligence

Palo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found only 12 reached production endpoints.

Malware & Threats

The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware.

Malware & Threats

The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version