Malicious Encrypted Reverse Shell via Netcat and GPG on Linux

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-09-15
Updated
2026-09-15

ATT&CK techniques

Execution → C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule detects a command pipeline that reads from a netcat listener decrypts the traffic with gpg and pipes it into a shell which the opportunistic Log4j campaign uses to run an encrypted reverse shell that evades network content inspection.

Related detections9 linkedT1071.001 — drag to rearrange
Suspicious Reverse Shell via Dev TCP or Netcat
Malicious Bash Dev-TCP Reverse Shell via Shell (via process_creation)
Malicious Named Pipe Netcat Reverse Shell via Shell (via process_creation)
Malicious axios NPM Supply Chain C2 Domain Resolution
Suspicious Base64 Decoded Payload Piped to Shell
Suspicious Shell Spawned by ActiveMQ Java Process
Malicious HarborWatch RAT Command and Control Beacon by User Agent (via proxy)
Suspicious UAT-10608 Credential Harvesting C2 Beacon via HTTP
Malicious BadIIS C2 Communication via lwxatisme User-Agent
Malicious Encrypted Reverse Shell via Netcat and GPG on Linux
Pivot detection · T1071.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.