Skip to comments.
Stealthy Linux backdoor malware spotted after three years of minding your business
The Register ^
| 29 April 2021
| Thomas Claburn
Posted on 04/30/2021 8:55:20 AM PDT by ShadowAce
click here to read article
Navigation: use the links below to view more comments.
first 1-20, 21-35 next last
1
posted on
04/30/2021 8:55:20 AM PDT
by
ShadowAce
To: rdb3; JosephW; martin_fierro; Still Thinking; zeugma; Vinnie; ironman; Egon; raybbr; AFreeBird; ...
Thanks to dayglored for the article!
2
posted on
04/30/2021 8:55:50 AM PDT
by
ShadowAce
(Linux - The Ultimate Windows Service Pack )
To: ShadowAce
I studied Oracle 9 for a year. Its platform is a form of Linux
To: ShadowAce
Was written by a Chinese “Backdoor man”?................
4
posted on
04/30/2021 8:58:36 AM PDT
by
Red Badger
(Jesus said there is no marriage in Heaven. That's why they call it Heaven.....................)
To: ShadowAce
“Chinese security outfit”
Isn’t that an oxymoron?
5
posted on
04/30/2021 8:59:58 AM PDT
by
Autonomous User
(During times of universal deceit, telling the truth becomes a revolutionary act.)
To: ShadowAce
Something keeps sneaking in and stealing my desktop icons on Linux Mint Cinnamon 18.3. I have to reboot to get them back.
[That seems to be a persistent problem with several versions of Linux.]
6
posted on
04/30/2021 9:00:21 AM PDT
by
TomGuy
To: ShadowAce
Isn’t “A Chinese security outfit” an oxymoron?
7
posted on
04/30/2021 9:01:35 AM PDT
by
Yo-Yo
(is the /sarc tag really necessary?)
To: Autonomous User
Ha! Beat me by 2 minutes!
8
posted on
04/30/2021 9:02:10 AM PDT
by
Yo-Yo
(is the /sarc tag really necessary?)
To: ShadowAce
“a suspicious ELF program that interacted with four command-and-control (C2) domains over the TCP HTTPS port 443 even though the protocol used isn’t actually TLS/SSL.”
Anyone could’ve told them that.
9
posted on
04/30/2021 9:02:35 AM PDT
by
lowbridge
To: ShadowAce
Oh, yeah, everybody knows that!?!
10
posted on
04/30/2021 9:02:44 AM PDT
by
immadashell
(New Planned Parenthood slogan: Black Babies’ Lives Don't Matter!)
To: Red Badger
A dude named “Mr. Wu”.... he was a window cleaner and then an air raid warden back in WWII. Just kidding- first came to mind.
George Formby (the Queen’s favourite morale booster in the Blitz):...”... if there’s a chink in your window, you’ll have another one at the door....” “ the girls all cover their laundry mark...” risque stuff for WWII.
https://www.youtube.com/watch?v=vnvgpeGxzak
11
posted on
04/30/2021 9:09:59 AM PDT
by
John S Mosby
(Sic Semper Tyrannis)
To: ShadowAce; All
Is the “backdoor” risk now closed by Linux updates? Since this came out? That is-— what is to be done? Read the details can’t figure out what a rotating trapdoor drop functionality— well, what is it. Says it is used for targeting individual machines.
Linux experts on FR— any suggestions?
12
posted on
04/30/2021 9:15:16 AM PDT
by
John S Mosby
(Sic Semper Tyrannis)
To: CharlesOConnell
Yup. Oracle is based off of Red Hat.
13
posted on
04/30/2021 9:15:37 AM PDT
by
ShadowAce
(Linux - The Ultimate Windows Service Pack )
To: TomGuy
I’ve never seen that happen before.
14
posted on
04/30/2021 9:16:08 AM PDT
by
ShadowAce
(Linux - The Ultimate Windows Service Pack )
To: ShadowAce
15
posted on
04/30/2021 9:17:21 AM PDT
by
dadfly
To: ShadowAce
According to Netlab, RotaJakiro supports 12 commands, including “Steal Sensitive Info,” “Upload Device Info,” “Deliver File/Plugin,” and three “Run Plugin” variants.
—
This article sounds like FUD designed to pitch security software.
For one, I seriously doubt any malware is going to have a function so obviously labeled “Steal Sensitive Info”. Secondly, what would constitute “sensitive info”?
16
posted on
04/30/2021 9:17:41 AM PDT
by
Flick Lives
(“Today we celebrate the first glorious anniversary of the Information Purification Directives.”)
To: John S Mosby
That is-— what is to be done? I believe that your chosen distro maintainer(s) should be able to filter it out.
17
posted on
04/30/2021 9:18:50 AM PDT
by
ShadowAce
(Linux - The Ultimate Windows Service Pack )
To: John S Mosby
Just so long as you don’t get a chink in your armor.................
18
posted on
04/30/2021 9:19:04 AM PDT
by
Red Badger
(Jesus said there is no marriage in Heaven. That's why they call it Heaven.....................)
To: TomGuy
Well, obviously someone has installed this backdoor on your system in a nefarious plot to steal your desktop icons and ultimately...CONTROL. THE. WORLD!!!!!
Or your window manager is crashing for some reason.
But it's probably definitely the first one.
To: ShadowAce
OK- thanks will check it out on their boards, maintenance etc.
20
posted on
04/30/2021 9:22:40 AM PDT
by
John S Mosby
(Sic Semper Tyrannis)
Navigation: use the links below to view more comments.
first 1-20, 21-35 next last
Disclaimer:
Opinions posted on Free Republic are those of the individual
posters and do not necessarily represent the opinion of Free Republic or its
management. All materials posted herein are protected by copyright law and the
exemption for fair use of copyrighted works.
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson