1. 5
  1.  

  2. 1

    I didn’t follow the one mention of ‘the fragmented file’. Does anyone get what it meant?

    1. 2

      Poor editing? I assume they just mean the backdoor file, possibly autocorrected from “Fokirtor”. It’s a shared library that they’re injecting into sshd, possibly via LD_PRELOAD. Then they delete the file to avoid leaving traces behind.

      1. 1

        I imagine that the file is fragmented into pieces to fit the available sshd traffic.