Security researchers identify new malware targeting Linux
welivesecurity.com
Security researchers identify new malware targeting Linux
1–10 of 70 posts
Re: Security researchers identify new malware targeting Linux
#2Re: Security researchers identify new malware targeting Linux
#3I understand the value of in-depth security reports, but the 5th time they told me "WolfsBane is the Linux counterpart of Gelsevirine, while FireWood is connected to Project Wood." I was wondering when I'd get to the meat and potatoes.
Re: Security researchers identify new malware targeting Linux
#4/lib/systemd/system/display-managerd.service
And a process called "kde".
Re: Security researchers identify new malware targeting Linux
#5If I am skimming this correctly, this is a C&C client allowing remote control over the network, and uses "a rootkit" for further compromise once it somehow gets installed? I understand the value of in-depth security reports, but the 5th time they told me "WolfsBane is the Linux counterpart of Gelsevirine, while FireWood is connected to Project Wood." I was wondering when I'd get to the meat and potatoes.
The report mentions: "we conclude ... exploited an unknown web application vulnerability ... ."
The chain of events, post initial exploit, is all very well but what was the initial point of entry? The IoCs etc are welcome - thanks.
Re: Security researchers identify new malware targeting Linux
#6Re: Security researchers identify new malware targeting Linux
#7Where is the backdoor coming from? If there's a backdoor, something is backdoored. An unknown exploit installing a rootkit and using a modified file, like usbdev.ko, is not a backdoor.
Which pakage / OS ships with the backdoor?
Or doesn't the author of TFA know the definition of a backdoor? Or is it me? I mean, to me the XZ utils exploit attempt was a backdoor (for example). But I see nothing here indicating the exploit they're talking about is a backdoor.
It reads like they classify anything opening ports and trying to evade detection as "backdoors".
Am I going nuts?
Re: Security researchers identify new malware targeting Linux
#8What's the point of these kinds of articles? Most Linux malware (including this one) are not sophisticated at all, built off of pre-existing rootkit code samples off Github and quite sloppy with leaving files and traces (".Xl1", modifying bashrc, really?). And there's a weird fixation on China here, is it just more anti-China propaganda?
Security companies attribute activity based on their observations. ESET- a Slovakian company- is no exception.
Re: Security researchers identify new malware targeting Linux
#9How it gets onto the system in the first place is the interesting (and dangerous) part, that sadly gets skimmed over here.
Re: Security researchers identify new malware targeting Linux
#10What's the point of these kinds of articles? Most Linux malware (including this one) are not sophisticated at all, built off of pre-existing rootkit code samples off Github and quite sloppy with leaving files and traces (".Xl1", modifying bashrc, really?). And there's a weird fixation on China here, is it just more anti-China propaganda?
Threat actors don't create malware to impress people; they do it to accomplish their goals. Apparently, this sample was sufficient for them. Security companies attribute activity based on their observations. ESET- a Slovakian company- is no exception.