Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Linux Hacks & Cracks

We have thousands of posts on a wide variety of open source and security topics, conveniently organized for searching or just browsing.

Discover Hacks/Cracks News

UNC2891: Banking Heists with Linux Malware Exploiting Physical Access

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

UNC2891 has been working its way through gaps in ATM security and broader banking security by slipping small hardware implants into places most teams assume are locked down. Investigators found Raspberry Pi systems sitting near ATM transaction switches, quietly feeding access back to the operators while Linux tooling handled the heavier work inside the network. The group paired that access with cloned cards and a mule network that turned compromised infrastructure into predictable cashouts.

Arch Linux Under Fire: DDoS Attack Enters Second Week

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

If you’ve tried pulling files from Arch’s main site, hit the AUR, or popped into their forums recently, then you’ve probably noticed things are off. Maybe you hit a dead end. Maybe you’re still cursing at your terminal trying to get a package. That’s because the Arch Linux project is under an ongoing DDoS (Distributed Denial of Service) attack, and it has been two weeks of intermittent outages. For an ecosystem as lightweight and DIY-friendly as Arch, these disruptions hit users and admins hard.

Plague: A Stealthy PAM-Based Backdoor Targeting Linux Systems

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Alright, let’s talk Plague. If you’re a Linux admin or someone knee-deep in securing systems, this little beast of a backdoor should have your full attention. It’s not like the typical brute-force, ransomware-type malware that makes headlines. This one’s subtle — it creeps into the very thing that defines user authentication on Linux machines: PAM (Pluggable Authentication Modules). And, to add insult to injury, it does so while keeping its tracks covered so well that no major antivirus solutions have been able to flag it.

From Windows to Linux: Gunra Ransomware's Strategic Evolution

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

You and I know Linux environments have always been the sturdy, reliable workhorses of IT ecosystems. For decades, they’ve been hailed as these relentless guardians of security—lean, stable, and, for a long time, not really worth the headache for ransomware groups. But that bubble is shrinking quickly. The Gunra ransomware group has changed the rules with its new Linux variant, and this one's got features designed to make Linux admins sweat. So, let’s dive into why this is more than just a footnote in the ransom-game evolution—and why you might need to rethink what you call “secure.”

Hackers Are Milking an Old Apache Flaw to Deploy Linuxsys Cryptominer

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Let’s talk straight: if you’re running Apache HTTP Server and you haven’t checked your version in a while, you might have a problem. An issue that’s now pretty ancient — CVE-2021-41773 — is still out there getting exploited by hackers, and they’re using it to deploy Linuxsys, a sneaky cryptocurrency miner. This isn’t your typical flash-in-the-pan malware campaign. It’s persistent, it’s clever, and honestly, it’s making a lot of admins look foolish for not locking down their setups.

Rust, C, & RaaS: Qilin Ransomware’s Approach to Cross-Platform Attacks

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

As a Linux admin, you're no stranger to juggling servers, permissions, and late-night emergencies. Let me introduce you to Qilin ransomware—a crafty, cross-platform adversary designed to unsettle even the most hardened infosec professional. If you haven’t yet encountered it, let me warn you—it’s not just another piece of malware floating around the threat landscape. This ransomware-as-a-service (RaaS) operation is polished, adaptable, and engineered with just the right mix of technical sophistication to demand your attention.

BERT Ransomware Takes Aim at Linux Systems

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

You know how it goes—Linux admins have long prided themselves on running systems that ransomware gangs mostly ignored. Sure, the occasional attack would trickle through, but if you were managing Linux environments, you weren’t waking up every other day wondering if your servers had been locked down by some cryptoware. Well, that sense of security is eroding. The BERT ransomware group just changed the game, targeting Linux systems and proving that ransomware gangs have their sights set on servers—and not just the Windows ones. If you’re running Linux setups for web hosting, cloud platforms, or pretty much any enterprise infrastructure, you need to pay attention to what’s happening here.

New Chaos RAT Malware Targets Windows and Linux Systems

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Alright, sysadmins and infosec pros, let’s talk about Chaos RAT. If you haven’t already crossed paths with this rather persistent piece of malware, it’s time you get familiar. This thing didn’t just pop up yesterday; it’s been lurking since 2017, originally as a legitimate remote access tool. But, like many open-source projects, it didn’t take long for someone to weaponize it. Fast forward to late 2022, and we’re seeing Chaos RAT meddling with Linux boxes, largely to mine cryptocurrency or snoop around for other nastiness. And now? Windows systems are in their crosshairs, too. Thanks, Golang.

Malicious Go Modules Delivering Disk-Wiping Payloads

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The world of open-source development offers boundless creativity, but it also comes with inherent risks, especially when trust is prioritized over security. Recently, Socket’s Threat Research Team uncovered a chilling supply-chain attack targeting developers who rely on Go modules—a popular tool in software engineering.

Curing Linux Rootkit Bypasses Security Monitoring

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

As security-minded Linux admins, we take pride in the reliability, flexibility, and security of our systems. The recent emergence of the Curing rootkit has brought attention to a gap that many security tools have overlooked, leaving our systems vulnerable to persistent infections that may go undetected for long periods.

UNC5174: SNOWLIGHT & VShell Malware Threat Overview for Linux

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Recently, the infamous China-linked threat actor UNC5174 has launched a sophisticated campaign targeting Linux systems, employing an evolved variant of the SNOWLIGHT malware and a new tool called VShell. This campaign's sophistication lies in its use of advanced techniques and an open-source Remote Access Trojan (RAT) notorious for its stealth and efficiency.

Mitigating Typosquatting Threats in Linux: Strategies for Developers

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Recent discoveries by Socket have exposed an elaborate typosquatting campaign targeting Linux and macOS developers through similar-sounding names for Go packages. This strategy dupes developers into downloading malicious packages that install malware loaders silently onto systems, potentially endangering entire networks.

Protecting Linux from Anubis Ransomware: Strategies and Best Practices

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The Anubis ransomware group has emerged as a growing threat, targeting Linux environments, NAS devices, and ESXi systems. What sets Anubis apart is its novel ransomware-as-a-service (RaaS) model featuring lucrative affiliate programs offering high revenue share programs with financial rewards to encourage attacks with incentives for dissemination.

Your message here