Linux Possible System Binary Backdoor — Detection Rule
The following analytic detects the creation or overwrite of commonly targeted Linux system binaries such as cat, ls, cp, ps, mv, netstat, ss, and lsof. Adversaries may replace these utilities with backdoored versions to hide malicious activity, harvest credentials, or maintain persistence while appearing to use legitimate system tools. This technique is associated with rootkit deployment and post-exploitation frameworks such as PANIX.