The Free Download Manager Linux Backdoor

Updated 5 Oct 2026 · Incident date 24 Jan 2020 · vendor binary

PackageFree Download Manager for Linux .deb (official) -> trojanized freedownloadmanager .deb served from deb.fdmpkg.org 2020-2022
Filepostinst

From 2020 to 2022, some Linux users who downloaded Free Download Manager received a trojanized Debian package from deb.fdmpkg.org. Its postinst script dropped two programs and set a cron job that ran every 10 minutes.

Kaspersky published the analysis in September 2023. The campaign became inactive in 2022. This page lists the files, hashes, and domains from the reports and shows how to check a machine.

What happened

The official site freedownloadmanager.org sent some Linux visitors to a different domain, deb.fdmpkg.org. That domain served a booby-trapped .deb package. BleepingComputer reports that the redirect used unknown criteria. The Hacker News reports that the criteria used a digital fingerprint of the system.

Kaspersky says the legitimate Free Download Manager version was released on 24 January 2020. The attackers improved their malware on 26 and 27 January 2020, as script comments show. Kaspersky found no sign of the redirect after 2022.

The package postinst script does three things:

The crond backdoor sends DNS requests that encode a fingerprint of the victim. The DNS reply gives the server address and port. The backdoor then opens a reverse shell over SSL or plain TCP. Kaspersky links it to the Bew backdoor family, seen since 2013.

The stealer, /var/tmp/bs, collects system information, browser history, saved passwords, cryptocurrency wallet files, and cloud credentials for AWS, Google Cloud, Oracle Cloud, and Azure. A third file, /var/tmp/atd, uploads the stealer output.

Affected versions

The sources do not give a version number. They name the Linux Free Download Manager .deb package served from deb.fdmpkg.org in 2020 to 2022.

Only some users received the bad package. Official .deb packages for the same product are the clean copy to compare against.

Indicators of compromise

How to check

Test for the three files that BleepingComputer tells users to look for.

ls -l /etc/cron.d/collect /var/tmp/crond /var/tmp/bs /var/tmp/atd

If any file exists, hash it and compare with the values above.

sha256sum /var/tmp/crond /var/tmp/bs /var/tmp/atd

Check the package source and the installed package.

grep -r fdmpkg /etc/apt/ 2>/dev/null; dpkg -l | grep -i freedownloadmanager

Search DNS logs for fdmpkg.org. The Free Download Manager team also published a bash script to check for compromise.

What to do now

  1. If any of the files exists, treat the machine as compromised.
  2. Delete /etc/cron.d/collect, /var/tmp/crond, and /var/tmp/bs, as BleepingComputer advises. Also remove /var/tmp/atd if it is present.
  3. Rotate all passwords, browser-saved logins, cryptocurrency wallet keys, and cloud credentials that the machine held.
  4. Block fdmpkg.org at the DNS or firewall level.
  5. Install software only from sources that you checked against the vendor's published hashes.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Free-prev --new Free-current
files scanned: 77 (2 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   Free.exe
           It runs other programs and restarts itself after a reboot.

Frequently asked questions

What was the Free Download Manager Linux backdoor?

From 2020 to 2022, some Linux users who downloaded Free Download Manager received a trojanized Debian package from deb.fdmpkg.org. Its postinst script installed a backdoor and a stealer.

How do I know if my Linux machine has the Free Download Manager malware?

Look for /etc/cron.d/collect, /var/tmp/crond, and /var/tmp/bs. If any exists, treat the machine as compromised and rotate its credentials.

Sources

  1. securelist.com/backdoored-free-download-manager-linux-malware/110465/
  2. bleepingcomputer.com/news/security/free-download-manager-site-redirected-linux-users-to-malware-for-years/
  3. thehackernews.com/2023/09/free-download-manager-site-compromised.html

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free