Most malware we catch in our honeypots has a server address baked in: an IP or a domain it calls home to. Defenders can block that address, and once it's listed on public feeds the malware is half-blind. The backdoor we looked at on 6 October 2026 avoids the problem. It carries no server address at all. Instead it asks a Telegram bot where to go, and the attacker can change the answer at any time by editing one pinned message in a chat.
It's not a new idea. Telegram has been used this way by Windows stealers for years. But this is a tidy, deliberate Linux version, built for eight different CPU architectures so it runs on anything from a cloud server to a home router, and as far as we can tell nobody had written it up yet.
How it reached our honeypot
At 19:31 UTC on 5 October 2026, a machine at 176.65.134[.]119 logged in to our Cowrie telnet honeypot with an empty username and password. It downloaded a small shell script, agent_i.sh, from itself and ran it. The same address served the installer and the malware, and did the logging in.
The installer is short and oddly chatty. Its comments read like an operator's notes from running it at scale: one says retrying downloads across all architectures "= 100MB = hang", another that duplicate copies caused "a reconnect storm (16.5M/day)". It tries each CPU architecture in turn, downloads the matching build, runs it with a --selftest flag and keeps the first one that answers SELFTEST_OK.
It also tests whether it's talking to a real machine. The attacker passes two random numbers, and the script prints their product. A real shell computes it; a honeypot that just echoes the script text back can't. It's a cheap and effective way to filter out traps like ours, and it's worth knowing about if you run one.
A day later the host was serving an updated installer. The new version can also download through node.js, with a comment saying that "node-only hosts exist (Next.js containers!)". That fits with another researcher's report linking the same address to React2Shell (CVE-2025-55182), the critical Next.js flaw disclosed in December 2025. We didn't see that delivery path ourselves.
What the backdoor does
We downloaded all eight builds inside our isolated lab: two x86, two ARM and four MIPS variants. They're the same program, written in Go, with the same settings in each. The function names left in the binaries make the design easy to read:
Finding its server. It calls the Telegram Bot API, reads the pinned message of one specific chat, and parses a server address out of it.
Taking commands. It connects to that server, says hello, and runs whatever shell commands it's sent.
Fallback. If the server is unreachable, it polls the bot itself for commands and replies through the same chat.
Staying put. It installs a systemd user service named
systemd-logind.service, described as "System Logging Helper" and set to restart forever. The realsystemd-logindis a system service and never runs as a user service, so the name is pure camouflage. It also adds a@rebootcron job and lines in.bashrcand.profile.Hiding. The running process renames itself
[kworker/0:1-events], so in a process list it looks like a kernel worker thread.
What we saw when we let it run
Our lab is offline by default. For this sample we made one exception: for a few minutes we let the x86_64 build reach exactly two destinations, the Telegram API and the attacker's port 4444, and blocked everything else.
It made a single encrypted connection to api.telegram.org and held it open, which is how a bot waits for new messages. It never tried the attacker's own server. For this build, at least, Telegram is the channel that's actually in use. We didn't decrypt that traffic, so we can't tell you what the pinned message says today.
Why this matters
Blocking Telegram isn't an option for most organisations, and a connection to api.telegram.org looks like normal app traffic. That's the point of the design: the attacker borrows a trusted service's reputation, and can move the real server whenever an address gets blocked. Takedowns have to happen at Telegram's end, so we've reported the bot to Telegram.
What gives this one away is on the host, not on the network.
What defenders can do
Look for the fake service. Any file at
~/.config/systemd/user/systemd-logind.serviceis suspicious, and so is any user service described as "System Logging Helper". Check every user account, not only root.Check your kernel threads. A process named
[kworker/...]that has an executable file behind it (ls -l /proc/PID/exe), or whose parent isn't process 2, isn't a kernel thread.Look in /tmp. Files named
/tmp/.g_x86_64,/tmp/.g_armv7and so on, or/tmp/.g_out, are the installer's staging files.Question Telegram traffic from servers. A web server or router that holds long connections to
api.telegram.orgdeserves a look.Close telnet. This arrived over telnet with no password. If a device still exposes telnet to the internet, turn it off or firewall it.
Use the published rules. Our repository has YARA and Sigma rules. We tested the YARA rules against all eight builds and both installer versions, and against about 40,000 other files from our honeypots with no false matches.
Key indicators
| Indicator | Role | Reference |
|---|---|---|
Telegram bot 8850962001 | Bot used as C2 (full token on ThreatFox) | ThreatFox |
176.65.134[.]119 | Installer and payload host, telnet login source | ThreatFox |
a4f5bec5e206... | x86_64 build (SHA-256 prefix); 7 more in iocs.csv | MalwareBazaar |
3f17516cc8a5... | agent_i.sh installer, updated version (SHA-256 prefix) | MalwareBazaar |
systemd-logind.service user unit | Persistence | iocs.csv |
[kworker/0:1-events] | Disguised process name | iocs.csv |
All hashes, defanged, are in the finding's iocs.csv, with the full technical write-up alongside. We publish the bot's ID but not its full token, since anyone holding the token can control the bot.
How we work
KSI Digital runs a WordPress bait and a Cowrie SSH/Telnet honeypot that record attacks and keep the files attackers download. We analyse samples in an isolated lab that is offline by default. When a live check is needed, we open only the specific destinations involved, for a few minutes, and we never interact with attacker accounts. Before we report an indicator we check it against existing feeds. More on our research page and in our methodology.
Indicators shared with ThreatFox and MalwareBazaar as ksi_digital: the Telegram bot and the eight builds on ThreatFox, the updated installer on MalwareBazaar, all on 6 October 2026. The bot and its chat were reported to Telegram's abuse team the same day. Corrections are welcome: open an issue on GitHub or email christophe@ksi-digital.com.
Tags
Concerned about these threats?
We test and monitor Indonesian organisations against the attacks our sensors see every day.
Our cybersecurity services