Netskope Threat Labs

ConnectBack

ATP Sandbox Adv. Heuristics

ConnectBack is a detection name for malware that establishes reverse connections from infected systems to criminal controlled servers. A reverse connection lets an operator reach machines behind firewalls and network address translation, because the compromised system initiates the outbound link. This technique is a foundation of remote access trojans and shells, so detections under this name usually signal active command and control rather than opportunistic file infections.

First seen
April 2022
Last seen
October 2026
Alert Name
Email-MSG.Backdoor.ConnectBack
Linux.Backdoor.ConnectBack
Linux.Exploit.ConnectBack