Live data from Hacker News

New ultra-stealthy Linux backdoor isn’t your everyday malware discovery

arstechnica.com

1–10 of 101 posts

Re: New ultra-stealthy Linux backdoor isn’t your everyday malware discovery

#7
post #2

Direct link to the blog post with all details https://www.intezer.com/blog/research/new-linux-threat-symbi...

Symbiote Deep-Dive: Analysis of a New, Nearly-Impossible-to-Detect Linux Threat

And disclosed in a blog post, with Nearly-Impossible-to-Read text.

Re: New ultra-stealthy Linux backdoor isn’t your everyday malware discovery

#8

LD_PRELOAD isn't a particularly new attack vector... and it is limited to the permissions of the user it is being run as. So it still needs an unpatched privilege excalation to do any real harm

> So it still needs an unpatched privilege excalation to do any real harm

https://xkcd.com/1200

All the important stuff you’d need to ruin someone’s life only needs their user account anyway, why is it such a relief if someone doesn’t get root access?

Re: New ultra-stealthy Linux backdoor isn’t your everyday malware discovery

#9
post #5

But how does it spread?

That's my exact question. This requires getting a .so on a device, and setting an environment variable for all users. The malware itself isn't too interesting, however clever they managed to hide it, but how they actually got it on the computers is.

Re: New ultra-stealthy Linux backdoor isn’t your everyday malware discovery

#10
post #7
post #2

Direct link to the blog post with all details https://www.intezer.com/blog/research/new-linux-threat-symbi...

Symbiote Deep-Dive: Analysis of a New, Nearly-Impossible-to-Detect Linux Threat And disclosed in a blog post, with Nearly-Impossible-to-Read text.

Do you mean text font/colour or the content itself?
Post reply on HN