ESET

Filip Jurcacko

Filip Jurcacko

2026

CinderRelay: The Linux Backbone of ScarCruft’s Covert Network

How does an APT group such as ScarCruft maintain long-term access to compromised infrastructure across multiple campaigns? In our research, we uncovered CinderRelay, the group's previously undocumented Linux server backdoor, which seems to hold the answer.

North Korea-aligned ScarCruft, also known as APT37 or Reaper, is an APT group active since at least 2012, primarily targeting South Korea. The group is well known for abusing cloud storage services for C&C purposes. It also compromises servers of legitimate websites and uses them to host C&C scripts and payloads.

Apart from providing typical root shell capability and stealing credentials on the compromised server, CinderRelay speaks a custom communication protocol that seemed somewhat familiar to us. We found that CinderRelay implements the server side of a protocol whose client side can be found in other ScarCruft Windows malware.

After analyzing the server part of the protocol, we determined that it is used in a covert network. Compromised machines connect to a CinderRelay-backdoored server, where the operator is connected as a master that can control the others. Additionally, we were able to identify live servers backdoored this way.

In this presentation, we share technical details of our investigation, starting with an overview of CinderRelay’s capabilities. We explain how we identified the custom communication protocol, and show evidence of a shared codebase across platforms. Then we look at the protocol and the covert network and explain its purpose. Finally, we talk about the identified backdoored servers and link them to previous ScarCruft activity.


About Filip Jurcacko

Filip Jurcacko is a Senior Malware Researcher at ESET. He focuses on hunting and analyzing sophisticated threats, producing in-depth technical research that contributes to ESET’s threat intelligence services and improves detection capabilities. Filip has presented his work at various conferences, including AVAR and LABScon. He holds a master’s degree in software engineering from the Slovak University of Technology in Bratislava.

In his free time, he likes to improve skills in CTF competitions.Â