Oh shit. https://www.helpnetsecurity.com/2025/06/23/lapdogs-shortleash-backdoor-linux-soho-devices/
researchers found a custom backdoor they called #ShortLeash, which gives attackers #root-level access and ensures #persistence. Once installed, it sets up a fake Nginx web server and generates a self-signed TLS certificate spoofing the LAPD. That certificate became a key fingerprint and helped researchers trace over 1,000 infected nodes worldwide. #infosec #malware #backdoor
researchers found a custom backdoor they called #ShortLeash, which gives attackers #root-level access and ensures #persistence. Once installed, it sets up a fake Nginx web server and generates a self-signed TLS certificate spoofing the LAPD. That certificate became a key fingerprint and helped researchers trace over 1,000 infected nodes worldwide. #infosec #malware #backdoor