Netskope Threat Labs

Rekoobe

ATP Sandbox Adv. HeuristicsAV

Rekoobe is a Linux backdoor associated with state sponsored actors that gives operators remote access to compromised servers. It typically arrives through compromised websites, trojanized installers, and other staged delivery, and its small footprint suits long term espionage on infrastructure that operators want to keep quietly. Detections under this name warrant a full investigation, because the family appears in targeted campaigns rather than opportunistic scans.

First seen
May 2022
Last seen
October 2026
Alert Name
Gen:Variant.Trojan.Linux.Rekoobe.1
Linux.Backdoor.Rekoobe
Linux.Trojan.Rekoobe
Trojan.Linux.Rekoobe.1
Trojan.Linux.Rekoobe.3
Trojan.Linux.Rekoobe.46
Trojan.Linux.Rekoobe.54
Trojan.Linux.Rekoobe.E
Trojan.Linux.Rekoobe.J