×
Login Register an account
Top Submissions Explore Upgoat Search Random Subverse Random Post Colorize! Site Rules
13

Chinese hackers have unleashed a never-before-seen Linux backdoor SprySOCKS borrows from open source Windows malware and adds new tricks.

submitted by dosvydanya_freedomz to technology 7 monthsSep 20, 2023 08:47:25 ago (+14/-1)     (arstechnica.com)

https://arstechnica.com/security/2023/09/never-before-seen-linux-backdoor-is-a-windows-malware-knockoff/

Researchers have discovered a never-before-seen backdoor for Linux that’s being used by a threat actor linked to the Chinese government.

The new backdoor originates from a Windows backdoor named Trochilus, which was first seen in 2015 by researchers from Arbor Networks, now known as Netscout. They said that Trochilus executed and ran only in memory, and the final payload never appeared on disks in most cases. That made the malware difficult to detect. Researchers from NHS Digital in the UK have said Trochilus was developed by APT10, an advanced persistent threat group linked to the Chinese government that also goes by the names Stone Panda and MenuPass.

Other groups eventually used it, and its source code has been available on GitHub for more than six years. Trochilus has been seen being used in campaigns that used a separate piece of malware known as RedLeaves.

In June, researchers from security firm Trend Micro found an encrypted binary file on a server known to be used by a group they had been tracking since 2021. By searching VirusTotal for the file name, ​​libmonitor.so.2, the researchers located an executable Linux file named “mkmon.” This executable contained credentials that could be used to decrypt the libmonitor.so.2 file and recover its original payload, leading the researchers to conclude that “mkmon” is an installation file that delivered and decrypted libmonitor.so.2.


3 comments block


[ - ] RMGoetbbels 1 point 7 monthsSep 20, 2023 10:08:43 ago (+1/-0)

I hope those chink fuckers enjoy my kitty file, it'll probably make them smile.

[ - ] Prairie 3 points 7 monthsSep 20, 2023 10:17:07 ago (+3/-0)

I hope it contain pictures of Tiananmen Square.

[ - ] NoRefunds 1 point 7 monthsSep 20, 2023 09:22:41 ago (+1/-0)

Those freaking Chinese putting back doors in our American operating systems, they are so smart