> - It opens a backdoor on the server and listens for TOR communications.
So a `lsof -iTCP` should list it, right? Is it using TCP port 9050 or a custom port?
EDIT: Ha, they are (not surprisingly) way ahead of me. From the article: "The malware continues to copy itself from memory to half a dozen other locations, with names that appear as conventional system files. It also drops a rootkit and a few popular Linux utilities that were modified to serve as user land rootkits (i.e. ldd, lsof)."