Xubuntu's website was hacked to spread a malware, fixed now
#1
Exclamation 
Quote:Xubuntu's website was the latest to fall victim to hackers. The attackers replaced the download links with a malicious one.

For those unaware, Xubuntu is one of the official flavors of Ubuntu, i.e. a fork/derivate of the distro. The name is a portmanteau of Xfce and Ubuntu.

Anyway, from what I can tell from user reports, the attackers replaced the download links on Xubuntu.org with a malicious one. So instead of downloading a .torrent file, it downloaded some ZIP archive that contained the malicious file.

Here is a screenshot of what the malware looks like.

[Image: Xubuntu-malware.jpg]
(Image courtesy reddit user Buty935)

Notice that it says Target Windows Version? That, combined with the EXE in the name, seems to suggest they were targeting Windows users. Perhaps users who are moving away from Windows 10, but weren't familiar with Linux or torrents? Despite what users might think, it is not a Linux malware. It installed itself to appdata, which only exists on Windows. The malware seems to be impersonating a GUI based downloader for Ubuntu. It stealthily runs some command prompts in the background to deliver the payload.

Continue Reading...
[-] The following 1 user says Thank You to harlan4096 for this post:
  • jasonX
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.3.5  Disabled ...Kool — 10:15
Hasleo software (formerly called EasyUE...
Hasleo Backup Suite ...jasonX — 21:06
Hasleo Backup Suite V5.6.2.1
Hasleo Backup Suit...harlan4096 — 17:41
Opera 128.0.5807.52
Hello! New upda...harlan4096 — 17:39
Brave 1.87.192
Release v1.87.192 ...harlan4096 — 17:38

[-]
Birthdays
Today's Birthdays
avatar (45)tukraNax
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (43)Hectorvot
avatar (51)knowhanPluts
avatar (39)Williamengiz
avatar (46)qaqapeti
avatar (44)battsourIonix
avatar (43)CedricSek
avatar (39)chasRex
avatar (45)walllMIZ
avatar (41)oconyho
avatar (33)uteluxix
avatar (47)piafcflene
avatar (39)Matthewkah
avatar (51)tersfargum
avatar (50)alfreExept
avatar (38)Charlesfibre
avatar (42)napasvem
avatar (44)diploJeoca
avatar (38)francisnj3
avatar (43)artmaGoork
avatar (41)RichardCisee
avatar (40)ebenofit
avatar (38)ykazawu

[-]
Online Staff
There are no staff members currently online.

>