Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Linux servers are being infected with a dangerous new malware

  • June 21, 2023
Total
0
Shares
0
0
0


Cybersecurity firm AhnLab’s Security Emergency response Center (ASEC) has uncovered an attack against, “inadequately managed” Linux SSH servers whereby malware is being installed and spread.

Most notable has been the installation of a Tsunami DDoS Bot, but ShellBot, XMRig CoinMiner, and Log Cleaner malware have also all been spotted.

Because Tsunami’s source code is publicly available, it has been used in numerous attacks against IoT devices and is often seen deployed alongside Mirai and Gafgyt, though Tsunami attacks on Linux servers are just as common.

Linux servers are being attacked by multiple malware

AhnLab says that the Secure Shell (SSH) service is prone to poor management, thus is a perfect opportunity for threat actors to exploit for attacks. SSH enables admins to log in remotely and control the system, but cyberattackers can also gain unauthorized access through brute force or a dictionary attack.

Alongside the DDoS bot that allows the execution of additional malicious commands, the CoinMiner can be especially detrimental to the performance of a machine as it gets to work mining for Monero.

The Log Cleaner also serves an important purpose in the attack as it assists in wiping away evidence of the attack, thus making it harder for victims to identify that their machine has become the subject.

While the consequences can be painful for IT admins, there are a few really simple steps that AhnLab highlights which can be taken to protect Linux servers from such attacks. 

Just like with any account, the cybersecurity firm recommends regularly changing the password which it says will help “protect the Linux server from brute force attacks and dictionary attacks.” Users should also frequently check for updates and patches, even with automatic updates enabled, to be able to iron out any bugs and vulnerabilities along the way.


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • Technology

DeepMind’s RoboCat learns to perform a range of robotics tasks

  • June 21, 2023
View Post
Next Article
  • Technology

FTC sues Amazon over ‘deceptive’ tactics used to sign up customers for Prime

  • June 21, 2023
View Post
You May Also Like
View Post
  • News

Ukraine’s War of Drones Runs Into an Obstacle: China

  • September 30, 2023
View Post
  • News

ICYMI: the 7 biggest tech stories of the week, from Meta Quest 3 to Raspberry Pi 5

  • September 30, 2023
View Post
  • News

A Windows 11 PC that’s smaller and lighter than the iPhone 15 Pro has been tested — just wait till someone hacks it into a Windows smartphone

  • September 30, 2023
View Post
  • News

Researchers find a way to make photos and muted videos ‘speak’ – here’s what it could mean for your privacy

  • September 30, 2023
View Post
  • News

Quordle today – hints and answers for Saturday, September 30 (game #614)

  • September 29, 2023
View Post
  • News

iCloud gets a makeover with a revamped look and quality-of-life upgrades

  • September 29, 2023
View Post
  • News

Pixel Watch 2 could get some Fitbit-style features to measure your stress levels

  • September 29, 2023
View Post
  • News

Elon Musk has removed a vital feature on X – fake news could soon get a lot worse

  • September 29, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.