New Crypto-Miner Attacks Linux Machines, Kills Other Miners and Anti-Malware
Quote:The Russian Dr.Web anti-malware maker discovered a new Linux threat embodied by a Trojan designed to work as a crypto-miner and as a dropper for some other nasty malware payloads such as DDoS backdoors and rootkits.

The new Trojan strain named Linux.BtcMine.174 by the Dr.Web team is a heavy 1,000-line shell script which comes with multiple modules that it will download and write to any folder with write permissions on the infiltrated Linux box.

Once it has managed to dump the extra malware payloads on the compromised machine, Linux.BtcMine.174 will use the nohup POSIX utility to launch itself as a daemon, redirecting its output to a nohup.out file to make detection more difficult.

After installing itself as a service, the Trojan downloads a Linux.BackDoor.Gates.9 Trojan payload that makes it possible for its masters to control the compromised machine and use it to execute DDoS attacks.

Because after compromising its Linux targets the Trojan is running under the privileges of the current user, almost never an administrator account, Linux.BtcMine.174 uses exploits such as Linux.Exploit.CVE-2016-5195 (known as DirtyCow) and Linux.Exploit.CVE-2013-2094 to escalate its privileges and completely take over the Linux machine.

[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096

Forum Jump:

Users browsing this thread: 1 Guest(s)
You have to register before you can post on our site.



Recent Posts
K-Lite Codec Pack 18.8.0 / 18.8.2 Update
Changes in 18.8.2 ...harlan4096 — 18:07
Apple Releases iOS 18.3.2 and macOS Sequ...
Apple Releases iOS...harlan4096 — 18:06
Opera 117.0.5408.93
Hello! A new st...harlan4096 — 18:01
Paint.NET 5.1.5
Paint.NET 5.1.5 - ...harlan4096 — 18:00
Brave 1.76.74
Release Channel 1....harlan4096 — 17:59

Today's Birthdays
avatar (41)napasvem
avatar (43)diploJeoca
Upcoming Birthdays
avatar (43)gapedDow
avatar (37)snorydar
avatar (42)Hectorvot
avatar (50)knowhanPluts
avatar (38)Williamengiz
avatar (45)qaqapeti
avatar (43)battsourIonix
avatar (42)CedricSek
avatar (38)chasRex
avatar (50)tersfargum
avatar (49)alfreExept
avatar (32)uteluxix
avatar (46)piafcflene
avatar (38)Matthewkah
avatar (37)Charlesfibre
avatar (37)francisnj3
avatar (42)artmaGoork
avatar (40)RichardCisee

Online Staff
There are no staff members currently online.
