Live data from Hacker News

EvilGnome: Rare Malware Spying on Linux Desktop Users

intezer.com

1–10 of 51 posts

Re: EvilGnome: Rare Malware Spying on Linux Desktop Users

#2
I imagine this is targeting Redhat Desktop installations then, as Red Hat is pretty big on GNOME, and as we all know, GNOME/Redhat has been at the spearhead of many unpopular systems, such as NetworkManager.

So my guess is, they're targeting Redhat Desktop, because it's the most likely Linux desktop to be seen in the corporate space. My old university had RHEL client machines.

Maybe they're just trying to get ahead of the curve with this?

Edit: Also, lately there has been more noise from more governments about using Linux, so yeah, getting ahead of the curve.

Re: EvilGnome: Rare Malware Spying on Linux Desktop Users

#3
post #2

I imagine this is targeting Redhat Desktop installations then, as Red Hat is pretty big on GNOME, and as we all know, GNOME/Redhat has been at the spearhead of many unpopular systems, such as NetworkManager. So my guess is, they're targeting Redhat Desktop, because it's the most likely Linux desktop to be seen in the corporate space. My old university had RHEL client machines. Maybe they're just trying to get ahead o…

Maybe, but don't Ubuntu and Debian also come with GNOME as the default desktop?

Re: EvilGnome: Rare Malware Spying on Linux Desktop Users

#4
post #2

I imagine this is targeting Redhat Desktop installations then, as Red Hat is pretty big on GNOME, and as we all know, GNOME/Redhat has been at the spearhead of many unpopular systems, such as NetworkManager. So my guess is, they're targeting Redhat Desktop, because it's the most likely Linux desktop to be seen in the corporate space. My old university had RHEL client machines. Maybe they're just trying to get ahead o…

Maybe, but don't Ubuntu and Debian also come with GNOME as the default desktop?

Actually that's a fair point. IIRC google has their own version of Ubuntu. However, I also expect google to be all over this kind of thing, but government and corporate, not so much.

Re: EvilGnome: Rare Malware Spying on Linux Desktop Users

#5
post #2

I imagine this is targeting Redhat Desktop installations then, as Red Hat is pretty big on GNOME, and as we all know, GNOME/Redhat has been at the spearhead of many unpopular systems, such as NetworkManager. So my guess is, they're targeting Redhat Desktop, because it's the most likely Linux desktop to be seen in the corporate space. My old university had RHEL client machines. Maybe they're just trying to get ahead o…

Maybe, but don't Ubuntu and Debian also come with GNOME as the default desktop?

They certainly do. Worth bearing in mind that this attack seems to be XOrg only and current versions of Ubuntu now default to Wayland.

Re: EvilGnome: Rare Malware Spying on Linux Desktop Users

#6

Earlier quoted context omitted.

Maybe, but don't Ubuntu and Debian also come with GNOME as the default desktop?

They certainly do. Worth bearing in mind that this attack seems to be XOrg only and current versions of Ubuntu now default to Wayland.

Not the LTS's which are over 90% of installs.

Re: EvilGnome: Rare Malware Spying on Linux Desktop Users

#7
The more uniform linux (and linux desktop) becomes the more easier and more valuable target it becomes as well.

Systemd, GNOME3, DBUS - they are essentially omnipresent on "modern" linuxes these days. The questionable safety that was provided by snowflake installs is evaporating fast.

Re: EvilGnome: Rare Malware Spying on Linux Desktop Users

#9

Earlier quoted context omitted.

Maybe, but don't Ubuntu and Debian also come with GNOME as the default desktop?

They certainly do. Worth bearing in mind that this attack seems to be XOrg only and current versions of Ubuntu now default to Wayland.

Only the "ShooterImage" component relies on Xorg (the other components work regardless of window system). Note that the reason Wayland isn't affected is because the malware doesn't use the API needed for taking screenshots.

Re: EvilGnome: Rare Malware Spying on Linux Desktop Users

#10
post #6

Earlier quoted context omitted.

They certainly do. Worth bearing in mind that this attack seems to be XOrg only and current versions of Ubuntu now default to Wayland.

Not the LTS's which are over 90% of installs.

18.04 LTS is GNOME
Post reply on HN