Live data from Hacker News

Perfctl: Stealthy malware targeting Linux servers

aquasec.com

51–53 of 53 posts

Re: Perfctl: Stealthy malware targeting Linux servers

#51
post #32

"CVE-2023-33246 is a vulnerability found in RocketMQ, which is a software that manages messages" A more appropriate but less clickbaity title would be "Stealthy malware targetting servers running RocketMQ"

The entry method is distinct from the exploitation or persistence method.

Like, how one picks a lock versus how one lives rent free in the attic without discovery.

Theyre not specifically dependent activities.

Re: Perfctl: Stealthy malware targeting Linux servers

#52
post #50

I've been dealing with something similar - maybe actually this for 2 months. There were so.e great insights from this researcher but they're missing some very fucked up elements of this malware. 1. I'm pretty sure it has. "fuck with it" scale. It leaves you alone if you don't fuck with it. In fact, I'd bet money that this malware did all the cryptocurrency shit for a reason like a bait and switch. 2. It effects andro…

Hi friend, I'm dealing with the same thing and agree with everything you said. ADDITIONALLY we found that it loves office printers, great attack vector to hit the whole office.

Also did you figure out why it reprograms display firmware? It spreads through displays and webcams optically. It can send or receive from either (same way NSA uses speakers as microphones basically). That's not the crazy part though, the crazy part is that it does human and canine retinal embeddings from either. It basically writes code on the retina and then that person can spread it to new systems. That turned out to be the biggest problem on our side. Sunglasses don't work.

Post reply on HN