A fourth octal digit sets three more bits (4 setuid, 2 setgid, 1 sticky), shown by ls -l as s or t in place of an execute character. setuid runs a binary with its owner's UID: that is how passwd writes /etc/shadow and sudo becomes root. setgid on a directory gives new files the directory's group, and new subdirectories inherit the bit. The sticky bit lets only a file's owner delete it, which is what makes a world-writable /tmp (1777) usable.
sudo mkdir shared && sudo chgrp webdev shared && sudo chmod 2775 shared
sudo -u deploy touch shared/a.txt; sudo -u deploy mkdir shared/sub
stat -c '%a %A %U:%G %n' shared shared/a.txt shared/sub /tmp2775 drwxrwsr-x root:webdev shared 644 -rw-r--r-- deploy:webdev shared/a.txt 2755 drwxr-sr-x deploy:webdev shared/sub 1777 drwxrwxrwt root:root /tmp
a.txt landed in group webdev and sub inherited the 2, but the file is 644 because sudo ran touch with umask 022: setgid supplies the group, a 002 umask the group write bit. Audit setuid files with sudo find / -xdev -type f -perm -4000 -ls: Ubuntu 26.04 225 lists 14, including two sudo binaries (sudo-rs and the original sudo.ws). A root-owned bash or python with mode 4755 there is a backdoor.