Live data from Hacker News

Perfctl: Stealthy malware targeting Linux servers

aquasec.com

31–40 of 53 posts

Re: Perfctl: Stealthy malware targeting Linux servers

#31
post #28
post #24

Heh, my work has a firewall policy: any activity towards TOR servers flags an alert and makes security contact you. If you don't confirm it was by design, they'll start full scale "computer compromised" procedure. (And if you do confirm it it was by design, then they'll ask you to change that design if possible :) ) I thought it was overly paranoid, but it seems that would have really helped in this case.

Unless youre doing security research, there close to zero legitimate uses of Tor for the average citizen.

There are plenty of reasons to use Tor. Not only to obfuscate location but to defend against mass surveillance, including that of the state [1]. Remember that Tor was developed originally and funded by the US State Department. Tor makes communications of LBTQ/Anti-authoritarian/journalist individuals safer in a world where the State Department has to put out advisories [2] about traveling while queer, a pride flag sticker is illegal and punishable by death or imprisonment in over 24 countries and journalists are imprisoned for talking to those who speak out.

Tor is an essential tool for all citizens -- Especially those in the US who would be targeted by those who seek infinite, unrestrained power.

[1] https://i.kym-cdn.com/photos/images/original/002/128/768/403...

[2] https://travel.state.gov/content/travel/en/traveladvisories/...

Re: Perfctl: Stealthy malware targeting Linux servers

#33
post #31
post #28

Earlier quoted context omitted.

Unless youre doing security research, there close to zero legitimate uses of Tor for the average citizen.

There are plenty of reasons to use Tor. Not only to obfuscate location but to defend against mass surveillance, including that of the state [1]. Remember that Tor was developed originally and funded by the US State Department. Tor makes communications of LBTQ/Anti-authoritarian/journalist individuals safer in a world where the State Department has to put out advisories [2] about traveling while queer, a pride flag st…

In theory, yes. In practice, the safety that Tor provides is in numbers, and the numbers just don't look good any more. By using Tor, you are entering a fairly small pool that you share with legit criminals and will be blocked and targeted accordingly. A good VPN like Mullvad is the saner option for most people.

Re: Perfctl: Stealthy malware targeting Linux servers

#34
post #10

Earlier quoted context omitted.

> In all the attacks observed, the malware was used to run a cryptominer I assume it starts by detecting a continuous 100% utilization of the cpu’s.

Supposedly it tones down it's activity while a user is logged in and waits for the machine to go idle. Another reason to have centralized performance monitoring.

Yes, but tools like htop show the average load over the last 15 min. So I assume that will show a high utilization.

Re: Perfctl: Stealthy malware targeting Linux servers

#35

Earlier quoted context omitted.

I hear Crowdstrike is king (≖ ͜ ≖)

To be fair, a system that rebooted and won't come back up IS pretty secure.

No, because it's a denial of service.

C-I-A triad: Confidentiality, Integrity, Availability.

A dead system is confidential, and if that's your criterion, then fine, but legitimate users may require access to intact data and services.

Re: Perfctl: Stealthy malware targeting Linux servers

#36
post #31
post #28

Earlier quoted context omitted.

Unless youre doing security research, there close to zero legitimate uses of Tor for the average citizen.

There are plenty of reasons to use Tor. Not only to obfuscate location but to defend against mass surveillance, including that of the state [1]. Remember that Tor was developed originally and funded by the US State Department. Tor makes communications of LBTQ/Anti-authoritarian/journalist individuals safer in a world where the State Department has to put out advisories [2] about traveling while queer, a pride flag st…

Detecting TOR traffic is trivial for state actors who control their local infrastructure. In the PRC, TOR usage is banned and the ban is enforced via packet inspection.

In any nation likely to target residents in the manners you have proposed, using TOR for any appreciable length of time puts a more prominent target on their backs than walking around with a pride flag sewn onto your jacket.

And fingerprinting TOR usage via deep packet inspection is the fancy-pants way of doing it. Many nations like Ethiopia, Kazakstan, China, and Iran also just prevent routing to known TOR exit nodes-- and they're all known.

Meanwhile TOR is like "just use a proxy brah", seemingly completely unaware that proxy usage is also detectable and that giving advice like that to vulnerable persons in unsafe countries is dangerous to those persons.

So then you get to the "Swiss cheese model" of disaster prevention where in order to safely use TOR you have to use it through a VPN that you connect to through a proxy (all of which is STILL detectable) and any mistake along the way due to not being absolutely and completely perfect in the configuration or usage of TOR will put you at risk of automated detection.

edit: you also, as a vulnerable user in an unsafe country who may not have consistent access to the internet or even speak English, must be stringently up-to-date on the software versions (e.g. the Ricochet vulnerability) of every product used in the TOR chain, which seems... unreasonable.

Re: Perfctl: Stealthy malware targeting Linux servers

#37
post #28
post #24

Heh, my work has a firewall policy: any activity towards TOR servers flags an alert and makes security contact you. If you don't confirm it was by design, they'll start full scale "computer compromised" procedure. (And if you do confirm it it was by design, then they'll ask you to change that design if possible :) ) I thought it was overly paranoid, but it seems that would have really helped in this case.

Unless youre doing security research, there close to zero legitimate uses of Tor for the average citizen.

You could make the same point without kicking up all the drama by saying there are close to zero legitimate reasons for a work computer on a work network to be reaching out to Tor.

Re: Perfctl: Stealthy malware targeting Linux servers

#38
post #33
post #31

Earlier quoted context omitted.

There are plenty of reasons to use Tor. Not only to obfuscate location but to defend against mass surveillance, including that of the state [1]. Remember that Tor was developed originally and funded by the US State Department. Tor makes communications of LBTQ/Anti-authoritarian/journalist individuals safer in a world where the State Department has to put out advisories [2] about traveling while queer, a pride flag st…

In theory, yes. In practice, the safety that Tor provides is in numbers, and the numbers just don't look good any more. By using Tor, you are entering a fairly small pool that you share with legit criminals and will be blocked and targeted accordingly. A good VPN like Mullvad is the saner option for most people.

In practice, even corporate greed steps in your way here... I can't even access reddit with Mullvad if I don't onionize it.

Re: Perfctl: Stealthy malware targeting Linux servers

#39

Earlier quoted context omitted.

To be fair, a system that rebooted and won't come back up IS pretty secure.

No, because it's a denial of service. C-I-A triad: Confidentiality, Integrity, Availability. A dead system is confidential, and if that's your criterion, then fine, but legitimate users may require access to intact data and services.

Sure, and availability in this sense is often forgotten, but I was only joking about Cloudstrike's ability to block malware.

A dead machine is difficult to infect with malware. You'd have to go out of your way to do so.

Re: Perfctl: Stealthy malware targeting Linux servers

#40
post #32

"CVE-2023-33246 is a vulnerability found in RocketMQ, which is a software that manages messages" A more appropriate but less clickbaity title would be "Stealthy malware targetting servers running RocketMQ"

The description of the payloads and of the hiding methods was educational though. Other malwares likely use similar techniques after the initial penetration.
Post reply on HN