The Free Download Manager Linux Backdoor
Updated 5 Oct 2026 · Incident date 24 Jan 2020 · vendor binary
Free Download Manager for Linux .deb (official) -> trojanized freedownloadmanager .deb served from deb.fdmpkg.org 2020-2022postinstFrom 2020 to 2022, some Linux users who downloaded Free Download Manager received a trojanized Debian package from deb.fdmpkg.org. Its postinst script dropped two programs and set a cron job that ran every 10 minutes.
Kaspersky published the analysis in September 2023. The campaign became inactive in 2022. This page lists the files, hashes, and domains from the reports and shows how to check a machine.
What happened
The official site freedownloadmanager.org sent some Linux visitors to a different domain, deb.fdmpkg.org. That domain served a booby-trapped .deb package. BleepingComputer reports that the redirect used unknown criteria. The Hacker News reports that the criteria used a digital fingerprint of the system.
Kaspersky says the legitimate Free Download Manager version was released on 24 January 2020. The attackers improved their malware on 26 and 27 January 2020, as script comments show. Kaspersky found no sign of the redirect after 2022.
The package postinst script does three things:
- Drops two ELF files,
/var/tmp/crondand/var/tmp/bs. - Writes
/etc/cron.d/collect, which starts/var/tmp/crondevery 10 minutes. - Opens a reverse shell through the backdoor.
The crond backdoor sends DNS requests that encode a fingerprint of the victim. The DNS reply gives the server address and port. The backdoor then opens a reverse shell over SSL or plain TCP. Kaspersky links it to the Bew backdoor family, seen since 2013.
The stealer, /var/tmp/bs, collects system information, browser history, saved passwords, cryptocurrency wallet files, and cloud credentials for AWS, Google Cloud, Oracle Cloud, and Azure. A third file, /var/tmp/atd, uploads the stealer output.
Affected versions
The sources do not give a version number. They name the Linux Free Download Manager .deb package served from deb.fdmpkg.org in 2020 to 2022.
- Package:
freedownloadmanager.debfromhttps://deb.fdmpkg[.]org/freedownloadmanager.deb - Malicious package SHA-256:
b77f63f14d0b2bde3f4f62f4323aad87194da11d71c117a487e18ff3f2cd468d - Period: 2020 to 2022
Only some users received the bad package. Official .deb packages for the same product are the clean copy to compare against.
Indicators of compromise
/etc/cron.d/collect/var/tmp/crond, SHA-2562214c7a0256f07ce7b7aab8f61ef9cbaff10a456c8b9f2a97d8f713abd660349/var/tmp/bs, SHA-25693358bfb6ee0caced889e94cd82f6f417965087203ca9a5fce8dc7f6e1b8a3ea/var/tmp/atd, SHA-256d73be6e13732d365412d71791e5eb1096c7bb13d6f7fd533d8c04392ca0b69b5- Domain
fdmpkg[.]organd all subdomains, in the form<hex string>.u.fdmpkg[.]org - Server address
172.111.48[.]101 - Example subdomains:
2c9bf1811ff428ef9ec999cc7544b43950947b0f.u.fdmpkg[.]org,c6d76b1748b67fbc21ab493281dd1c7a558e3047.u.fdmpkg[.]org - Shutdown message
Waiting for process: crond, reported by infected users on several distributions
How to check
Test for the three files that BleepingComputer tells users to look for.
ls -l /etc/cron.d/collect /var/tmp/crond /var/tmp/bs /var/tmp/atd
If any file exists, hash it and compare with the values above.
sha256sum /var/tmp/crond /var/tmp/bs /var/tmp/atd
Check the package source and the installed package.
grep -r fdmpkg /etc/apt/ 2>/dev/null; dpkg -l | grep -i freedownloadmanager
Search DNS logs for fdmpkg.org. The Free Download Manager team also published a bash script to check for compromise.
What to do now
- If any of the files exists, treat the machine as compromised.
- Delete
/etc/cron.d/collect,/var/tmp/crond, and/var/tmp/bs, as BleepingComputer advises. Also remove/var/tmp/atdif it is present. - Rotate all passwords, browser-saved logins, cryptocurrency wallet keys, and cloud credentials that the machine held.
- Block
fdmpkg.orgat the DNS or firewall level. - Install software only from sources that you checked against the vendor's published hashes.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 77 (2 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE Free.exe It runs other programs and restarts itself after a reboot.
Frequently asked questions
What was the Free Download Manager Linux backdoor?
From 2020 to 2022, some Linux users who downloaded Free Download Manager received a trojanized Debian package from deb.fdmpkg.org. Its postinst script installed a backdoor and a stealer.
How do I know if my Linux machine has the Free Download Manager malware?
Look for /etc/cron.d/collect, /var/tmp/crond, and /var/tmp/bs. If any exists, treat the machine as compromised and rotate its credentials.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.