Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Chinese hackers are exploiting a new Linux backdoor to target national governments

  • September 19, 2023
Total
0
Shares
0
0
0


A Chinese threat actor was observed targeting multiple governments around the world with a new Linux backdoor, according to new findings from Trend Micro.

As reported by BleepingComputer, the group is called Earth Lusca, and has been active in the first half of the year, targeting government organizations in Southeast Asia, Central Asia, the Balkans, and elsewhere. The organizations were mostly focused on foreign affairs, technology, and telecommunications. Earth Lusca’s goal seems to be espionage.

To compromise their targets’ endpoints, the group used multiple n-day unauthenticated remote code execution flaws, most of which were discovered and addressed between 2019 and 2022. Through these flaws, they’d drop Cobalt Strike beacons, which were later used to deploy a new Linux backdoor called SprySOCKS.

Stealing files and more

SprySOCKS is not brand new, though. Its code is a mix of multiple other malware variants, it was said, including the Trochilus open-source malware for Windows, a backdoor for the same OS called RedLeaves, and Derusbi, which is a Linux malware. 

Its key functionalities include system information harvesting, starting an interactive shell using the PTY subsystem, listing network connections, managing SOCKS proxy configurations, as well as the usual capabilities such as uploading and downloading files. 

Besides SprySOCKS, the group was seen dropping a Linux ELF injector dubbed “mandibule”, as well. Mandible itself was tweaked and changed, but in a relatively sloppy manner, it seems, as researchers found debug messages and symbols behind, indicating that the developers weren’t really paying attention that much. 

SprySOCKS, on the other hand, is in active development, the researchers concluded. So far, they managed to obtain two versions of the backdoor, including v1.1 and v.1.3.6. 

The best way to protect against such threats is to make sure all endpoints are patched regularly.

More from TechRadar Pro


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • Technology

Pryon raises $100M to index and analyze enterprise data

  • September 19, 2023
View Post
Next Article
  • Technology

Remote launches new HR platform for companies with a “global-first” approach

  • September 19, 2023
View Post
You May Also Like
View Post
  • News

If you wanted an Intel Meteor Lake CPU for your next desktop PC, we’ve got some bad news

  • September 27, 2023
View Post
  • News

Apple’s rumored iPhone 15 Pro overheating fix could come with a catch

  • September 27, 2023
View Post
  • News

PC sales are starting to pick up – but you still shouldn’t buy one just yet

  • September 27, 2023
View Post
  • News

EA Sports has delisted almost every FIFA game from digital storefronts

  • September 27, 2023
View Post
  • News

LinkedIn is making its platform more accessible with some useful Microsoft tools

  • September 27, 2023
View Post
  • News

Apple TV Plus is getting two wildly different movies I simply cannot wait for

  • September 27, 2023
View Post
  • News

Ubisoft talks about its cloud gaming deal with Microsoft, believes that “it will take time” for game streaming to take off

  • September 27, 2023
View Post
  • News

World of Warcraft brings back series legend Chris Metzen to help craft “the next generation of adventures”

  • September 27, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.