Beyond the Surface: Mapping the Facefish Rootkit’s Digital Footprint
In the shadowy world of cyber threats, some malware aims not just to steal data, but to disappear.

In the shadowy world of cyber threats, some malware aims not just to steal data, but to disappear. Rootkits like Facefish are designed precisely for this: to hide their presence and maintain stealthy, persistent control over compromised Linux systems, often to steal valuable SSH credentials for sale on the dark web.
At Alpha Cyber , we specialize in uncovering these hidden threats. This post will briefly explain the danger of Facefish and demonstrate how vital tools like VirusTotal are in mapping its invisible infrastructure.
The Facefish Rootkit: A Stealthy Linux Predator
Facefish is a sophisticated Linux rootkit. It’s a two-part threat: a dropper (initial installer) and the rootkit itself. Its main capabilities include:
- Stealth & Persistence: Operating at a low level (user-mode, using LD_PRELOAD to hook system functions), Facefish manipulates SSH/SSHD processes to hide its malicious activities from traditional detection tools. It’s designed to remain undetected for long periods.
- Credential Theft: Its primary objective is to steal user login credentials and SSH keys, providing attackers with high-privileged access.
- Backdoor Functionality: It establishes a backdoor for remote command execution and reverse shells, giving attackers full control over the compromised system.
- Encrypted C2: It uses a custom, encrypted (Blowfish cipher) communication protocol with its Command and Control (C2) servers, making network traffic harder to analyze.
Mapping the Invisible: VirusTotal and Facefish Infrastructure
While Facefish tries to be invisible on a compromised host, its supporting infrastructure leaves traces. When our threat hunters encounter an indicator related to Facefish (like a suspicious IP or file hash), we leverage tools like VirusTotal to piece together the attacker’s network.
For a rootkit like Facefish, a “map” created using VirusTotal can reveal:
- Dropper & Rootkit Samples: Analyzing the malicious files themselves (droppers, rootkit binaries) shows how many security vendors detect them and their known behaviors.
- Associated C2 Domains/IPs: Uncovering the C2 servers Facefish uses for communication and data exfiltration. VirusTotal helps link files to the domains they communicate with.
- DNS & Whois Data: Historical information about the C2 domains can reveal patterns in how the attackers register and manage their infrastructure.
- Community Contributions: Insights from other security researchers worldwide who have analyzed Facefish samples, providing a broader context and identifying related attack components.
This intelligence helps us identify the operational backbone of the Facefish rootkit, allowing for proactive blocking and detection.
Fortify Your Linux Environments
Rootkits like Facefish highlight the need for advanced cybersecurity. Traditional antivirus often isn’t enough when malware aims to vanish at the OS level.
At Alpha Cyber, we offer:
- Advanced Endpoint Detection & Response (EDR): Specialized monitoring for Linux environments that can detect rootkit behaviors and anomalous system calls.
- Proactive Threat Hunting: Our experts actively search for the subtle signs of rootkit presence and C2 communications that bypass automated alerts.
- Vulnerability Management: Identifying and patching weaknesses, like those in web panels (e.g., CWP exploits used by Facefish), that attackers leverage for initial access.
- SSH Security Hardening: Best practices for securing SSH keys, configurations, and monitoring SSH activity for suspicious logins or key exfiltration.
Don’t let rootkits hide in plain sight. Protect your critical Linux infrastructure from the unseen.
Is your Linux environment truly secure from stealthy rootkits?
Contact Alpha Cyber today for a consultation. Let us help you defend against the most evasive threats.



