Advanced Linux backdoor found in the wild escaped AV detection

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12Jcpru4ncipZ=O5x_4kVPvBCZXN4H_KempEjsgxj22aLQ@mail.gmail.com>
'Researchers say they’ve discovered an advanced piece of Linux malware
that has escaped detection by antivirus products and appears to be
actively used in targeted attacks.

HiddenWasp, as the malware has been dubbed, is a fully developed suite
of malware that includes a trojan, rootkit, and initial deployment
script, researchers at security firm Intezer reported on Wednesday. At
the time Intezer’s post went live, the VirusTotal malware service
indicated Hidden Wasp wasn’t detected by any of the 59 antivirus
engines it tracks, although some have now begun to flag it. Time
stamps in one of the 10 files Intezer analyzed indicated it was
created last month. The command and control server that infected
computers report to remained operational at the time this article was
being prepared.

Some of the evidence analyzed—including code showing that the
computers it infects are already compromised by the same
attackers—indicated that HiddenWasp is likely a later stage of malware
that gets served to targets of interest who have already been infected
by an earlier stage. It’s not clear how many computers have been
infected or how any earlier related stages get installed. With the
ability to download and execute code, upload files, and perform a
variety of other commands, the purpose of the malware appears to be to
remotely control the computers it infects. That's different from most
Linux malware, which exists to perform denial of service attacks or
mine cryptocurrencies.'

-- source: https://arstechnica.com/information-technology/2019/05/advanced-linux-backdoor-found-in-the-wild-escaped-av-detection/

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.