In September 2023, FortiGuard Labs’ vigilant team uncovered a significant development in the IZ1H9 Mirai-based DDoS campaign. . This campaign, known for its aggressive tactics, had strengthened its arsenal with a formidable array of thirteen exploits, potentially endangering Linux-based systems across various organizations. The IZ1H9 campaign threatens a wide range of users across any organization that utilizes Linux-based systems. Its potential impact is critical, as remote attackers can gain full control of vulnerable systems, effectively turning them into bots under the attacker’s command. . FortiGuard Labs has uncovered a fresh DDoS campaign leveraging Mirai, which targets Linux flaws, representing a significant danger.. Mirai Botnet, DDoS Campaign, Linux Exploits, Threat Detection. . LinuxSecurity.com Team
Russian digital espionage group Fancy Bear has incorporated a new Linux-based malware dubbed “Drovorub” into their attack campaigns, according to the National Security Agency (NSA) and the FBI. . In their joint advisory last year, the NSA and FBI explained the Linux-based malware — dubbed “Drovorub” by researchers — consists of three different components: a kernel module rootkit, a file transfer and port forwarding kit and a command-and-control (C&C) tool. They found that these traits made it possible for Fancy Bear, also known as “APT28” and “Strontium,” to download and upload files, execute arbitrary commands as root and port forward network traffic on other hosts. . The hacker collective Cozy Bear has launched attacks on governmental organizations utilizing advanced Windows exploits, broadening their cyber capabilities through the tool known as Mimikatz.. Fancy Bear, Linux Malware, Cyber Threats, Digital Espionage, Drovorub. . LinuxSecurity.com Team
Have you heard about the attack campaign that is targeting Docker users with cryptocurrency mining malware via exposed APIs? . Hackers are attempting to compromise Docker servers en masse via exposed APIs in order to spread cryptocurrency mining malware, according to researchers. Aqua Security claimed to have tracked the organized campaign for several months, revealing that thousands of attempts to hijack misconfigured Docker Daemon API ports are taking place almost every single day. “In this attack, the attackers exploit a misconfigured Docker API port to run an Ubuntu container with the kinsing malicious malware, which in turn runs a cryptominer and then attempts to spread the malware to other containers and hosts,” it explained. . Cybercriminals are increasingly exploiting Docker containers by taking advantage of unsecured APIs to deploy crypto-mining malware.. Docker Security, Crypto Malware, Container Exploits, API Vulnerabilities. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.