Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Linux Trojan captures audio and takes screenshots
InfoWorld ^ | Jan 20, 2016 | Jim Lynch

Posted on 01/20/2016 8:26:27 PM PST by Utilizer

Security is something that is always on the minds of users these days, and that includes those who use Linux. TechWeek Europe has a disturbing article about a Linux trojan that captures audio and takes screenshots.

It remains to be seen how widespread this Trojan is among Linux users and what the exact attack vector is for it.

Steve McCaskill reports for TechWeek Europe:

Security researchers have found a new Linux Trojan capable of taking screenshots of infected systems and even recording sound.

Russian anti-virus firm Dr Web says that once the Linux.Ekoms.1 malware is launched it checks for two specific files – one related to Dropbox and another related to Firefox. If it finds neither of the files, it makes a copy of itself and launches from a new directory.

"If the launch is successful, Linux.Ekoms.1 connects to the server whose addresses are hard-coded in its body," said the company. "All information transmitted between the server and Linux.Ekoms.1 is encrypted. The encryption is initially performed using the public key; and the decryption is executed by implementing the RSA_public_decrypt function to the received data.

"Every 30 seconds the service takes a screenshot and saves it to a temporal folder in the JPEG format with a name in the ss%d-%s.sst format, where %s is a timestamp. If the file is not saved, the Trojan tries to save it in the BMP format."

(Excerpt) Read more at infoworld.com ...


TOPICS: Computers/Internet
KEYWORDS: apple; bsd; dropbox; firefox; internet; ios; jimlynch; linux; macos; malware; microsoft; osx; security; stevemccaskill; trojanware; unix; windows
Not certain this is all that common yet, but it might bear looking into for those of us using the 'nix OS.
1 posted on 01/20/2016 8:26:27 PM PST by Utilizer
[ Post Reply | Private Reply | View Replies]

To: Utilizer; Disambiguator

Bookmarking.


2 posted on 01/20/2016 8:43:16 PM PST by Disambiguator
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

They really should tell us the server so we can block it at the router.


3 posted on 01/20/2016 9:08:46 PM PST by Dalberg-Acton
[ Post Reply | Private Reply | To 1 | View Replies]

To: All

Sorry, minor correction”

“- one related to Dropbox and another related to Firefox.”

Apologies for the strange-character mistake.


4 posted on 01/20/2016 9:19:54 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

This should be a capital offense.


5 posted on 01/20/2016 10:04:52 PM PST by Ray76
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson