New ultra-stealthy Linux backdoor isn’t your everyday malware discovery
1–10 of 101 posts
Re: New ultra-stealthy Linux backdoor isn’t your everyday malware discovery
#2Re: New ultra-stealthy Linux backdoor isn’t your everyday malware discovery
#3Re: New ultra-stealthy Linux backdoor isn’t your everyday malware discovery
#4Re: New ultra-stealthy Linux backdoor isn’t your everyday malware discovery
#5Re: New ultra-stealthy Linux backdoor isn’t your everyday malware discovery
#6Re: New ultra-stealthy Linux backdoor isn’t your everyday malware discovery
#7Direct link to the blog post with all details https://www.intezer.com/blog/research/new-linux-threat-symbi...
And disclosed in a blog post, with Nearly-Impossible-to-Read text.
Re: New ultra-stealthy Linux backdoor isn’t your everyday malware discovery
#8LD_PRELOAD isn't a particularly new attack vector... and it is limited to the permissions of the user it is being run as. So it still needs an unpatched privilege excalation to do any real harm
All the important stuff you’d need to ruin someone’s life only needs their user account anyway, why is it such a relief if someone doesn’t get root access?
Re: New ultra-stealthy Linux backdoor isn’t your everyday malware discovery
#9But how does it spread?
Re: New ultra-stealthy Linux backdoor isn’t your everyday malware discovery
#10Direct link to the blog post with all details https://www.intezer.com/blog/research/new-linux-threat-symbi...
Symbiote Deep-Dive: Analysis of a New, Nearly-Impossible-to-Detect Linux Threat And disclosed in a blog post, with Nearly-Impossible-to-Read text.