The Free Download Manager Linux Package Backdoor
Updated 5 Oct 2026 · Incident date 24 Jan 2020 · vendor binary
Free Download Manager Debian package served to a share of Linux visitors from the official site, 2020 to 2022postinstFrom 2020 to 2022, the Free Download Manager website sent some Linux visitors to a malicious Debian package. The package installed a backdoor and an information stealer. Kaspersky found the campaign in September 2023.
The redirect did not happen for every visitor. This hid the scale of the attack for more than three years.
What happened
The download page of Free Download Manager sometimes redirected Linux users to deb.fdmpkg.org instead of the real file host. Kaspersky's Securelist report says the package was released on 24 January 2020. Comments in the post-install script suggest that the malware was written on 26 and 27 January 2020.
The postinst script installed two ELF binaries and created a cron job. The job ran /var/tmp/crond every 10 minutes. This binary is a DNS-based backdoor, a modified version of the Bew backdoor first seen in 2013. A second binary, /var/tmp/bs, handles SSL connections. A third, /var/tmp/atd, uploads data. A bash stealer collects system information, browser history, saved passwords, cryptocurrency wallet files, and credentials for AWS, Google Cloud, Oracle Cloud, and Azure.
BleepingComputer reports that Kaspersky first got no response from the vendor, and that the vendor acknowledged the issue and published a statement on 16 September 2023. The redirection stopped in 2022 for reasons that no source explains. The Hacker News says the sources found no clear attribution.
Affected versions
The sources do not give a version number. The affected item is the Debian package served from deb.fdmpkg.org/freedownloadmanager.deb to a share of Linux visitors between 2020 and 2022. The legitimate package came from files2.freedownloadmanager.org. Only Linux users who got the redirect are affected. Windows users are not part of this report.
Indicators of compromise
- Files:
/etc/cron.d/collect,/var/tmp/crond,/var/tmp/bs,/var/tmp/atd - SHA-256 of the malicious .deb:
b77f63f14d0b2bde3f4f62f4323aad87194da11d71c117a487e18ff3f2cd468d - SHA-256 of
crond:2214c7a0256f07ce7b7aab8f61ef9cbaff10a456c8b9f2a97d8f713abd660349 - SHA-256 of
bs:93358bfb6ee0caced889e94cd82f6f417965087203ca9a5fce8dc7f6e1b8a3ea - SHA-256 of
atd:d73be6e13732d365412d71791e5eb1096c7bb13d6f7fd533d8c04392ca0b69b5 - Domains:
fdmpkg.organd its subdomains,deb.fdmpkg.org - IP address:
172.111.48.101
How to check
Look for the files the package drops. The command only lists files.
ls -l /etc/cron.d/collect /var/tmp/crond /var/tmp/bs /var/tmp/atd 2>/dev/null grep -r fdmpkg /etc/apt /var/log/apt 2>/dev/null
If any file exists, hash it and compare it with the list above.
sha256sum /var/tmp/crond /var/tmp/bs /var/tmp/atd
What to do now
- If any of the files exist, treat the machine as compromised.
- Remove
/etc/cron.d/collect,/var/tmp/crond,/var/tmp/bs, and/var/tmp/atd. Kaspersky lists these steps. - Rotate every credential on the machine: browser passwords, shell history secrets, wallet keys, and cloud keys for AWS, Google Cloud, Oracle Cloud, and Azure.
- Rebuild the machine if it holds sensitive data. A backdoor gives the operator remote control.
- Install software from a source whose hash you can verify.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 38 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED Free.exe It now downloads from the internet, reads saved passwords and access keys and restarts itself after a reboot. It did not before.
Frequently asked questions
How did the Free Download Manager Linux attack work?
The vendor site redirected some Linux visitors to deb.fdmpkg.org, which served a Debian package. Its postinst script installed a backdoor, a stealer, and a cron job.
How do I know if Free Download Manager infected my Linux machine?
Check for /etc/cron.d/collect, /var/tmp/crond, /var/tmp/bs, and /var/tmp/atd. If any exists, treat the machine as compromised.
How long did the Free Download Manager Linux attack last?
Kaspersky reports that it ran from 2020 to 2022, and researchers found it in September 2023.
Sources
More supply chain attacks
- JDownloader official site installer swap 6 May 2026
- CPUID CPU-Z / HWMonitor download compromise 9 Apr 2026
- DAEMON Tools trojanized installers 8 Apr 2026
- eScan antivirus update server compromise (2026) 20 Jan 2026
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.