RedTail Packed Multiple Linux Binaries for One Intrusion

SANS guest diary author Aaron Ng says a DShield/Cowrie honeypot captured a RedTail Linux payload bundle built for several processor types, including ARM, ARM64, i686, RISC-V, and x86-64. The package also came with deployment and cleanup scripts. The deployment script checked the host architecture and launched the matching RedTail executable. In dynamic analysis, the x86-64 sample changed its visible process name, killed other processes, stopped one filesystem-monitoring process used in the test, and opened a TCP listening socket. For defenders watching mixed Linux fleets, the point is not a single infected host type but an operator who prepared one package to adapt across CPUs. That makes architecture assumptions and single-sample triage less reliable when you are trying to judge how far the tooling can spread.

Part of the PlainSec briefing for 2026-09-11

Every edition of this story: RedTail Packed Multiple Linux Binaries for One Intrusion

Sources