The Linux Mint Backdoored ISO Attack
Updated 5 Oct 2026 · Incident date 20 Feb 2016 · other
Linux Mint 17.3 Cinnamon ISO linked from linuxmint.com on 20 February 2016/var/lib/man.cyThe Linux Mint 17.3 Cinnamon ISO was backdoored for downloads on 20 February 2016. Attackers broke into the Linux Mint website and changed the download link to point at an ISO that they hosted.
The ISO contained a Tsunami IRC backdoor. Other Linux Mint editions and versions were not affected.
What happened
Attackers changed the download link for Linux Mint 17.3 Cinnamon so that it served a poisoned ISO. The Hacker News reports that the attackers entered through the WordPress blog on the site and got a shell as www-data. Only downloads on 20 February 2016 were affected.
Help Net Security reports that the Linux Mint team announced the breach on 21 February 2016. It also reports that the attacker had copied the forum database on 28 January and 18 February 2016. That database held user names, email addresses, encrypted passwords and profile data. The team said that torrent downloads and direct HTTP links were not affected.
Kaspersky's Securelist analyzed the ISO. It detects the backdoor as HEUR:Backdoor.Linux.Tsunami.bh. The backdoor is controlled through IRC with no encryption on the command channel. It can flood targets with UDP and TCP traffic, download files and run commands. The ISO stores the source code at /var/lib/man.cy and compiles it into a program named apt-cache at start-up. Securelist saw about 50 clients in the IRC channel #mint. It also saw the attacker send an smbtree -N command to look for network shares.
The Hacker News reports that the attackers came back after the first cleanup. The team then took linuxmint.com offline.
Affected versions
- Linux Mint 17.3 Cinnamon edition ISO, downloaded on 20 February 2016 only.
- Not affected: other editions, other versions, and downloads from before or after that day (The Hacker News).
- Not affected: torrent downloads and direct HTTP links (Help Net Security).
Indicators of compromise
- File:
/var/lib/man.cy(backdoor source code). - A compiled program named
apt-cachethat the backdoor starts. The realapt-cacheis a normal system tool, so compare it with a clean install. - MD5 hashes that Securelist lists for the malware:
d945f9b959f76afe24f3a804fe316806and7d590864618866c225ede058f1ba61f0. - Domains:
updates.absentvodka.com,updates.mintylinux.com,eggstrawdinarry.mylittlerepo.com,linuxmint.kernel-org.org. - IP address:
5.104.175.212(Securelist, The Hacker News). - IRC channel:
#mint.
How to check
You can check the install for the backdoor source file and compare the ISO you saved with the checksum from the Linux Mint project. Run these commands. They only read files.
ls -l /var/lib/man.cy
md5sum ~/Downloads/linuxmint-17.3-cinnamon-64bit.iso
If /var/lib/man.cy exists, the machine ran the backdoored ISO. Compare the MD5 value with the one the Linux Mint project published for the genuine ISO. The file name above is an example. Use the name of your file.
What to do now
- Take the computer offline (The Hacker News).
- Back up personal data. Do not copy programs or scripts.
- Reinstall the operating system from a clean ISO, or format the partition.
- Change passwords for sensitive accounts and email from a clean device.
- If you used the same password on forums.linuxmint.com, change it elsewhere too (Help Net Security).
- For future downloads, verify the checksum and the signature from the project before you install. Securelist advises signatures from a PKI instead of hash checks alone.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 87 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE Linux.exe It downloads from the internet and runs other programs.
Frequently asked questions
Which Linux Mint ISO was backdoored?
The Linux Mint 17.3 Cinnamon edition ISO, downloaded on 20 February 2016. Other editions and versions were not affected.
How do I know if my Linux Mint ISO was infected?
Check whether the file /var/lib/man.cy exists on the installed system. Also compare the MD5 checksum of the ISO with the value that the Linux Mint project published for the genuine file.
How did hackers backdoor the Linux Mint ISO?
They entered through the WordPress blog on the Linux Mint site, got a shell as www-data, and changed the download link to an ISO that they hosted.
Sources
More supply chain attacks
- Gravity Forms WordPress plugin compromise 9 Jul 2025
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.