Description
ConnectBack is a detection name for malware that establishes reverse connections from infected systems to criminal controlled servers. A reverse connection lets an operator reach machines behind firewalls and network address translation, because the compromised system initiates the outbound link. This technique is a foundation of remote access trojans and shells, so detections under this name usually signal active command and control rather than opportunistic file infections.
Stats
- First seen
- April 2022
- Last seen
- October 2026
Alert name variants
| Alert Name |
|---|
| Email-MSG.Backdoor.ConnectBack |
| Linux.Backdoor.ConnectBack |
| Linux.Exploit.ConnectBack |