May 31, 2023

Researchers have discovered a new Linux backdoor on compromised ecommerce servers that intercepts and exfiltrates sensitive customer information, including credit card details.

The malicious agent, dubbed linux_avp is written in Golang, and was discovered by researchers at Sansec, who were approached by an affected merchant who couldn’t seem to get rid of malware from his store. Once deployed will take commands from china C2C.


The discovery of the malware across ecommerce stores all around the world comes mere days before the Black Friday shopping extravaganza. The attackers first run automated tests to probe ecommerce websites against dozens of known vulnerabilities. As soon as one is found, it installs a backdoor and uploads the linux_avp server agent.

The linux_avp agent injects fake payment forms on checkout pages displayed to customers of the compromised stores. Further analysis reveals that the fake payment form written in PHP is designed to steal and exfiltrate customers’ payment and personal information. 

The researchers note that the IP address used to fetch the fake payment page, is hosted in Hong Kong and has previously been observed as a skimming exfiltration endpoint in July and August of this year.


Researchers notes that it found the malware on several US and EU-based servers, though last checked, no other antivirus vendor recognized this malware. 

