The Linux Mint Backdoored ISO Attack

Updated 5 Oct 2026 · Incident date 20 Feb 2016 · other

PackageLinux Mint 17.3 Cinnamon ISO linked from linuxmint.com on 20 February 2016
File/var/lib/man.cy

The Linux Mint 17.3 Cinnamon ISO was backdoored for downloads on 20 February 2016. Attackers broke into the Linux Mint website and changed the download link to point at an ISO that they hosted.

The ISO contained a Tsunami IRC backdoor. Other Linux Mint editions and versions were not affected.

What happened

Attackers changed the download link for Linux Mint 17.3 Cinnamon so that it served a poisoned ISO. The Hacker News reports that the attackers entered through the WordPress blog on the site and got a shell as www-data. Only downloads on 20 February 2016 were affected.

Help Net Security reports that the Linux Mint team announced the breach on 21 February 2016. It also reports that the attacker had copied the forum database on 28 January and 18 February 2016. That database held user names, email addresses, encrypted passwords and profile data. The team said that torrent downloads and direct HTTP links were not affected.

Kaspersky's Securelist analyzed the ISO. It detects the backdoor as HEUR:Backdoor.Linux.Tsunami.bh. The backdoor is controlled through IRC with no encryption on the command channel. It can flood targets with UDP and TCP traffic, download files and run commands. The ISO stores the source code at /var/lib/man.cy and compiles it into a program named apt-cache at start-up. Securelist saw about 50 clients in the IRC channel #mint. It also saw the attacker send an smbtree -N command to look for network shares.

The Hacker News reports that the attackers came back after the first cleanup. The team then took linuxmint.com offline.

Affected versions

Indicators of compromise

How to check

You can check the install for the backdoor source file and compare the ISO you saved with the checksum from the Linux Mint project. Run these commands. They only read files.

ls -l /var/lib/man.cy
md5sum ~/Downloads/linuxmint-17.3-cinnamon-64bit.iso

If /var/lib/man.cy exists, the machine ran the backdoored ISO. Compare the MD5 value with the one the Linux Mint project published for the genuine ISO. The file name above is an example. Use the name of your file.

What to do now

  1. Take the computer offline (The Hacker News).
  2. Back up personal data. Do not copy programs or scripts.
  3. Reinstall the operating system from a clean ISO, or format the partition.
  4. Change passwords for sensitive accounts and email from a clean device.
  5. If you used the same password on forums.linuxmint.com, change it elsewhere too (Help Net Security).
  6. For future downloads, verify the checksum and the signature from the project before you install. Securelist advises signatures from a PKI instead of hash checks alone.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Linux-prev --new Linux-current
files scanned: 87 (1 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   Linux.exe
           It downloads from the internet and runs other programs.

Frequently asked questions

Which Linux Mint ISO was backdoored?

The Linux Mint 17.3 Cinnamon edition ISO, downloaded on 20 February 2016. Other editions and versions were not affected.

How do I know if my Linux Mint ISO was infected?

Check whether the file /var/lib/man.cy exists on the installed system. Also compare the MD5 checksum of the ISO with the value that the Linux Mint project published for the genuine file.

How did hackers backdoor the Linux Mint ISO?

They entered through the WordPress blog on the Linux Mint site, got a shell as www-data, and changed the download link to an ISO that they hosted.

Sources

  1. securelist.com/beware-of-backdoored-linux-mint-isos/73893/
  2. thehackernews.com/2016/02/linux-mint-hack.html
  3. helpnetsecurity.com/2016/02/22/linux-mint-hack-backdoored-isos-stolen-forums-database/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free