Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Musk sued for falsely accusing Jewish man of joining a neo-Nazi brawl

    October 2, 2023

    Is Bitcoin’s Bottom In Sight? Expert Analysis Says Yes

    October 2, 2023

    Bengals are sticking with a limited Joe Burrow. Here’s why.

    October 2, 2023
    Facebook Twitter Instagram
    • About Us
    • Contact Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Facebook Twitter Instagram Pinterest Vimeo
    Weis
    • Home
    • Crypto
      1. Cryptocurrency Live Price
      2. View All

      Musk sued for falsely accusing Jewish man of joining a neo-Nazi brawl

      October 2, 2023

      Is Bitcoin’s Bottom In Sight? Expert Analysis Says Yes

      October 2, 2023

      Bengals are sticking with a limited Joe Burrow. Here’s why.

      October 2, 2023

      Victorian bushfires threaten homes and lives as towns warned to take shelter | Australia news

      October 2, 2023

      Is Bitcoin’s Bottom In Sight? Expert Analysis Says Yes

      October 2, 2023

      Tradecurve Unveiles Revolutionary TradFi Platform Amid Ongoing Crypto Market Recovery

      October 2, 2023

      Adidas and Moncler Collab Features AI ‘Adventurers’ and NFTs

      October 2, 2023

      US Government Frames Bitcoin Privacy As “Criminal”

      October 2, 2023
    • Insurance

      Insurtech Artificial Labs and Tier 2 Consulting announce partnership

      October 2, 2023

      Allianz extends tenure of CEO Oliver Bäte

      October 2, 2023

      FEMA Sets Up Free Legal Help for Florida Idalia Victims

      October 2, 2023

      Reinsurance pricing to normalise in late 2024, says Goldman Sachs

      October 2, 2023

      Celebrating vulnerability, networking and future talent with women in insurance

      October 2, 2023
    • International News

      Victorian bushfires threaten homes and lives as towns warned to take shelter | Australia news

      October 2, 2023

      ‘They’re going to come at you’: Paola Egonu on racism and volleyball | Racism

      October 2, 2023

      Asian Champions League: Saudi side Al-Ittihad refuse to play in Iran due to statue

      October 2, 2023

      Trump wants judge criminally charged at New York fraud trial – live

      October 2, 2023

      Serbia says it has reduced troop presence near Kosovo – DW – 10/02/2023

      October 2, 2023
    • Politics

      Bowman defends fire alarm scandal by repeating talking point about being ‘in a rush’ to vote

      October 2, 2023

      Sunak fails to hand WhatsApp messages from time as chancellor to Covid inquiry | Covid inquiry

      October 2, 2023

      Supreme Court opens term with case on prison terms for drug offenders

      October 2, 2023

      Trump civil fraud trial in New York begins

      October 2, 2023

      Denis Mukwege, DRC’s Nobel prize winner, announces presidency bid | Elections News

      October 2, 2023
    • Sports

      Bengals are sticking with a limited Joe Burrow. Here’s why.

      October 2, 2023

      Mom of Nathaniel and Josh Lowe battling cancer, won’t attend Rangers-Rays playoff series

      October 2, 2023

      Zion Williamson Had Hilarious Response to What He Worked on This Offseason

      October 2, 2023

      Lakers’ LeBron James: ‘I Don’t Know’ If 2023-24 Will Be My Final NBA Season | News, Scores, Highlights, Stats, and Rumors

      October 2, 2023

      Fever’s Aliyah Boston named unanimous WNBA Rookie of the Year

      October 2, 2023
    • Tech

      Musk sued for falsely accusing Jewish man of joining a neo-Nazi brawl

      October 2, 2023

      Apple secretly working on Google Search killer for ‘years,’ probably won’t ever launch

      October 2, 2023

      The best all-in-one computers of 2023

      October 2, 2023

      Best Horror, Sci-Fi, and Fantasy Films Streaming October 2023

      October 2, 2023

      Amazon Drops Its Kindle Scribe E Ink Tablet Down to New All-Time Low Price

      October 2, 2023
    • Shop
    Subscribe
    Weis
    Home»Tech»Chinese hackers have unleashed a never-before-seen Linux backdoor
    Tech

    Chinese hackers have unleashed a never-before-seen Linux backdoor

    AuthorBy AuthorSeptember 19, 2023No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Trojan horse over blocks of hexadecimal programming codes.  Concept illustration of online hacking, computer spyware, malware and ransomware.

    Researchers have discovered a never-before-seen backdoor for Linux used by a threat actor linked to the Chinese government.

    The new backdoor comes from a Windows backdoor named Trochilus, which was first spotted in 2015 by researchers from Arbor Networks, now known as Netscout. They say that Trochilus kills and runs only in memory, and the final payload never appears on the disks in most cases. That makes it difficult to detect malware. Researchers from the UK’s NHS Digital say Trochilus was created by APT10, an advanced persistent threat group linked to the Chinese government also known as Stone Panda and MenuPass.

    Other groups eventually used it, and its source code has been available on GitHub for over six years. Trochilus has been seen used in campaigns that use a separate piece of malware known as RedLeaves.

    In June, researchers from the security firm Trend Micro found an encrypted binary file on a server known to be used by a group they have been tracking since 2021. Through a search on VirusTotal for the file name, libmonitor.so.2, the researchers found an executable Linux file named “mkmon”. This executable has credentials that can be used to decrypt the libmonitor.so.2 file and recover its original payload, leading the researchers to conclude that “mkmon” is an installation file that delivers decrypts libmonitor.so.2.

    The Linux malware ports many of the functions found in Trochilus and combines them with a new implementation of Socket Secure (SOCKS). Trend Micro researchers eventually named their discovery SprySOCKS, with “spry” referring to its fast behavior and the added SOCKS component.

    SprySOCKS implements standard backdoor capabilities, including collecting system information, opening an interactive remote shell for controlling compromised systems, listing network connections, and creating a proxy. based on the SOCKS protocol for uploading files and other data between the compromised system and the one controlled by the attacker. command server. The following table shows some of the capabilities:

    Advertisement

    Message ID Notes
    0x09 Gets machine information
    0x0a Starts the interactive shell
    0x0b Data is written to the interactive shell
    0x0d Stops the interactive shell
    0x0e Lists network connections (parameters: “ip”, “port”, “commName”, “connectType”)
    0x0f Sending packet (parameter: “target”)
    0x14, 0x19 Sends the initialization packet
    0x16 Creates and configures the client
    0x17 Lists network connections (parameters: “tcp_port”, “udp_port”, “http_port”, “listen_type”, “listen_port”)
    0x23 Creates a SOCKS proxy
    0x24 Terminates the SOCKS proxy
    0x25 Forward SOCKS proxy data
    0x2a Uploading a file (parameters: “transfer_id”, “size”)
    0x2b Got a file transfer ID
    0x2c File download (parameters: “state”, “transferId”, “packageId”, “packageCount”, “file_size”)
    0x2d Gets transfer status (parameters: “state”, “transferId”, “result”, “packageId”)
    0x3c Enumerated files in root /
    0x3d Enumerates the files in the directory
    0x3e Delete the file
    0x3f Creates a directory
    0x40 File name changed
    0x41 No surgery
    0x42 Related operations 0x3c – 0x40 (srcPath, destPath)

    After decrypting the binary and finding SprySOCKS, the researchers used the information they found to search VirusTotal for related files. Their search contained a version of the malware with release number 1.1. The version found by Trend Micro is 1.3.6. The multiple versions suggest that the backdoor is currently under development.

    The command and control server attached to SprySOCKS bears significant similarities to a server used in a campaign with another piece of Windows malware known as RedLeaves. Like SprySOCKS, RedLeaves is also based on Trochilus. The strings found in Trochilus and RedLeaves are also found in the SOCKS component added to SprySOCKS. The SOCKS code is borrowed from HP-Socket, a high-performance network framework with Chinese origins.

    Trend Micro attributes SprySOCKS to a threat actor named Earth Lusca. Researchers discovered the group in 2021 and documented it the following year. Earth Lusca targets organizations around the world, especially governments in Asia. It uses social engineering to lure targets to watering-hole sites where the targets are infected with malware. Besides showing an interest in espionage activities, Earth Lusca seems to be financially motivated, with sights set on gambling and cryptocurrency companies.

    The same Earth Lusca server that hosts SprySOCKS also delivers payloads known as Cobalt Strike and Winnti. Cobalt Strike is a hacking tool used by security professionals and threat actors. It provides a full set of tools for finding and exploiting vulnerabilities. Earth Lusca uses it to expand its reach after gaining an initial hold within a targeted environment. Winnti, on the other hand, is the name of two sets of malware that have been used for more than a decade as well as the identifier for several different threat groups, all connected to the Chinese government’s intelligence apparatus, which is one of the world’s largest hacking syndicates.

    Monday’s Trend Micro report provides IP addresses, file hashes, and other evidence that people can use to determine if they’ve been compromised.

    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleCompromised private keys led to $70M theft
    Next Article Old Republic forms accident & health subsidiary
    Author
    • Website

    Related Posts

    Tech

    Musk sued for falsely accusing Jewish man of joining a neo-Nazi brawl

    October 2, 2023
    Tech

    Apple secretly working on Google Search killer for ‘years,’ probably won’t ever launch

    October 2, 2023
    Tech

    The best all-in-one computers of 2023

    October 2, 2023
    Add A Comment

    Leave A Reply Cancel Reply

    Top Posts

    Musk sued for falsely accusing Jewish man of joining a neo-Nazi brawl

    October 2, 2023

    Tablet PC Market to Witness Exponential Growth by 2028, Sources Say

    January 11, 2020

    Save $25 on Philips Wired Headphone For A Great Sounding Over-Ear Headphone

    January 12, 2020
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Crypto

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    AuthorJanuary 15, 2021
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    AuthorJanuary 15, 2021
    8.9
    Uncategorized

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    AuthorJanuary 15, 2021

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Musk sued for falsely accusing Jewish man of joining a neo-Nazi brawl

    October 2, 2023

    Tablet PC Market to Witness Exponential Growth by 2028, Sources Say

    January 11, 2020

    Save $25 on Philips Wired Headphone For A Great Sounding Over-Ear Headphone

    January 12, 2020
    Our Picks

    Musk sued for falsely accusing Jewish man of joining a neo-Nazi brawl

    October 2, 2023

    Is Bitcoin’s Bottom In Sight? Expert Analysis Says Yes

    October 2, 2023

    Bengals are sticking with a limited Joe Burrow. Here’s why.

    October 2, 2023

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.