Live data from Hacker News

EvilGnome: Rare Malware Spying on Linux Desktop Users

intezer.com

11–20 of 51 posts

Re: EvilGnome: Rare Malware Spying on Linux Desktop Users

#11
>EvilGnome’s functionalities include desktop screenshots, file stealing, allowing capturing audio recording from the user’s microphone and the ability to download and execute further modules.

I'm glad this is still considered malware in the Linux world at least, and not just "analytics"

Re: EvilGnome: Rare Malware Spying on Linux Desktop Users

#12
post #7

The more uniform linux (and linux desktop) becomes the more easier and more valuable target it becomes as well. Systemd, GNOME3, DBUS - they are essentially omnipresent on "modern" linuxes these days. The questionable safety that was provided by snowflake installs is evaporating fast.

Ed. Never mind, can't read apparently.

Re: EvilGnome: Rare Malware Spying on Linux Desktop Users

#13
post #8

Note that this requires for a user to actually download and run this malware, it doesn't randomly get into someone's computer by itself: > This implant is delivered in the form of a self-extracting archive shell script created with makeself

Most malware is. The question becomes how good they are at tricking people to install it.

Re: EvilGnome: Rare Malware Spying on Linux Desktop Users

#14
post #4

Earlier quoted context omitted.

Maybe, but don't Ubuntu and Debian also come with GNOME as the default desktop?

Actually that's a fair point. IIRC google has their own version of Ubuntu. However, I also expect google to be all over this kind of thing, but government and corporate, not so much.

FYI they use Debian now: https://www.zdnet.com/article/google-moves-to-debian-for-in-...

Re: EvilGnome: Rare Malware Spying on Linux Desktop Users

#15

Earlier quoted context omitted.

Maybe, but don't Ubuntu and Debian also come with GNOME as the default desktop?

They certainly do. Worth bearing in mind that this attack seems to be XOrg only and current versions of Ubuntu now default to Wayland.

>Ubuntu now default to Wayland.

I think Ubuntu changed their minds and went back to Xorg, also Wayland+GNOME Shell has the terrible issue where the shell crashes would bring down your session and you lose all your work.

Debian just switched to Wayland so in the fallowing months we will see the effects, it could be a new pulse audio situation where you will get a lot of "fixes" starting by removing Wayland.

Re: EvilGnome: Rare Malware Spying on Linux Desktop Users

#16
post #12
post #7

The more uniform linux (and linux desktop) becomes the more easier and more valuable target it becomes as well. Systemd, GNOME3, DBUS - they are essentially omnipresent on "modern" linuxes these days. The questionable safety that was provided by snowflake installs is evaporating fast.

Ed. Never mind, can't read apparently.

I reads the opposite. He said such systems are easier targets because of uniformity.

Re: EvilGnome: Rare Malware Spying on Linux Desktop Users

#17
post #12
post #7

The more uniform linux (and linux desktop) becomes the more easier and more valuable target it becomes as well. Systemd, GNOME3, DBUS - they are essentially omnipresent on "modern" linuxes these days. The questionable safety that was provided by snowflake installs is evaporating fast.

Ed. Never mind, can't read apparently.

Didn't look like it to me. More that security by obscurity in having heterogeneous infrastructure across different distributions no longer applies, not that systemD was improving the situation.

Re: EvilGnome: Rare Malware Spying on Linux Desktop Users

#18
This incident made me think that the hackers planned to hijack some popular extension. this would make the more damage.

My (unpopular) opinion is that GNOME should see what are the most used extensions, accept that people want those feature and bring those features into GNOME or make those official extension and not third party, so you at least control what most people would install.

Re: EvilGnome: Rare Malware Spying on Linux Desktop Users

#20
post #2

I imagine this is targeting Redhat Desktop installations then, as Red Hat is pretty big on GNOME, and as we all know, GNOME/Redhat has been at the spearhead of many unpopular systems, such as NetworkManager. So my guess is, they're targeting Redhat Desktop, because it's the most likely Linux desktop to be seen in the corporate space. My old university had RHEL client machines. Maybe they're just trying to get ahead o…

I would expect Gnome to be the window manager of >80% of Linux installs. I don't think Redhat is particularly special in this regard, even if it is a particularly juicy target.
Post reply on HN