GSocket Backdoor Delivered Through Bash Script, (Fri, Mar 20th)

2026-03-22T07:23:46Z91f46bd6bc068140a273cd39096f63bc91fffb920af2e507f09b6abe0aa3b417
DShieldGSocketLinuxadminerbackdoorbash scriptcowriehoneypotindicatorsipv4-mapped-ipv6iranbotmalicious scriptnetwork reconnaissancephpmyadminproxy-scansscanningtelnet

What happened

SANS ISC diary entries (Mar 16–20, 2026) report multiple attacker activities. Key item: discovery of a malicious Bash script that installs a GSocket backdoor on a victim Linux host; the delivery vector and origin are unknown. Other reports from honeypots/cowrie and DShield include a notable message string ("MAGIC_PAYLOAD_KILLER_HERE_OR_LEAVE_EMPTY_iranbot_was_here") and activity from IP 64.89.161.198 between 30 Jan–22 Feb 2026 (portscans, successful Telnet login, web access). Additional entries describe widespread scans targeting adminer/phpmyadmin, proxy URL abuse (including use of IPv4-maped

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
91f46bd6bc068140a273cd39096f63bc91fffb920af2e507f09b6abe0aa3b417
Enrichment time
2026-03-22T07:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · GSocket Backdoor Delivered Through Bash Script, (Fri, Mar 20th) · Baitaphish