Explore top 10 tips to secure your open-source projects now. Read More
×A Linux version of the multi-platform backdoor malware called DinodasRAT has been spotted in cyberattacks across several countries. The malware, also known as XDealer, is a C++-based threat that can harvest sensitive data from compromised systems. . The prevalent and evasive malware can be attributed to China-nexus threat actors. This discovery raises significant security implications and emphasizes the importance of proactive measures for Linux administrators and infosec professionals. What Are the Security Implications of DinodasRAT Linux Malware? The emergence of a Linux variant of DinodasRAT is a development concern for security practitioners in the Linux community. Its targeted attacks on Red Hat-based distributions and Ubuntu Linux indicate the need for heightened vigilance in these environments. As Linux admins and system administrators, we must stay up-to-date with the latest threat intelligence and security advisories to protect our infrastructure from this evolving threat landscape. One intriguing aspect of this malware is DinodasRAT's persistence mechanism through SystemV or SystemD startup scripts. This technique enables the malware to establish a foothold on the compromised system, making it challenging to detect and mitigate. Linux admins and sysadmins must thoroughly review the startup scripts on their machines to ensure that this backdoor is not leveraging them. DinodasRAT also can perform various malicious activities, such as file operations, process enumeration, and shell command execution. This comprehensive feature set indicates that the malware operators have significant control over the compromised systems, posing a severe threat to data exfiltration and espionage. Infosec professionals should consider conducting thorough security assessments and penetration tests to identify potential vulnerabilities this malware may exploit. Moreover, DinodasRAT's utilization of the Tiny Encryption Algorithm (TEA) for encrypting command and control (C2) communicationshighlights the sophistication of this threat. This raises questions about how organizations can effectively monitor and detect such encrypted communications, especially in environments with many Linux servers. Investing in robust threat intelligence solutions and maintaining secure network monitoring practices becomes critical to identifying any malicious activity associated with DinodasRAT. The implications of DinodasRAT's presence in cyberattacks across multiple countries cannot be ignored. It prompts us to reevaluate our security strategies and consider potential long-term consequences. As security practitioners, we must question whether our current defenses are adequately equipped to withstand such targeted threats. This article reminds Linux admins, sysadmins, and infosec professionals to continuously enhance their knowledge and skills to safeguard their systems against evolving malware variants. Our Final Thoughts on DinodasRAT Linux Malware The discovery of the Linux version of DinodasRAT highlights the evolving nature of cyber threats and the importance of maintaining robust security measures. Linux admins, infosec professionals, and sysadmins must remain vigilant, update their defenses, and adopt proactive security practices to protect their infrastructure from this and similar malware variants. By leveraging threat intelligence, conducting regular security assessments, and implementing encryption monitoring techniques, we can counter the impact of DinodasRAT and mitigate its potential damage. . DynoesRAT represents significant threats for Unix environments, especially regarding information theft and ongoing presence methods.. DinodasRAT Linux, Backdoor Threats, Malware Security, Linux Admins, Cybersecurity Risk. . Dave Wreski
A Chinese-speaking hacking group tracked as ‘DragonSpark’ was observed employing Golang source code interpretation to evade detection while launching espionage attacks against organizations in East Asia. . The attacks are tracked by SentinelLabs , whose researchers report that DragonSpark relies on a little-known open-source tool called SparkRAT to steal sensitive data from compromised systems, execute commands, perform lateral network movement, and more. The threat actors leverage compromised infrastructure in China, Taiwan, and Singapore to launch their attacks, while the intrusion vector observed by SentinelLabs is vulnerable MySQL database servers exposed online. . PhantomStrike employs Python code obfuscation to remain undetected during surveillance missions aimed at Southeast Asian organizations.. DragonSpark Espionage, Golang Interpretation, East Asia Cyber Attacks, Open Source Malware. . LinuxSecurity.com Team
Open Source lends itself to a new way of certifying software: Continuous Assurance. In this approach, automated tools and processes ensure that, as code changes, it continually satisfies compliance, quality, and security requirements. "Continuous Assurance integrates directly into development and benefits from the always-up-to-date nature of cloud services, making it a perfect match for Open Source." . Sonatype’s 2020 State of the Software Supply Chain Report found that next generation cyber-attacks actively targeting open-source soft- ware projects increased 430% over the past 12 months. Industry and the Open Source communities recognize heightened security risks and are working to solve these. For example, in August 2020 the Linux Foundation launched the Open Source Security Foundation (OpenSSF), billing itself as “a cross-industry collaboration that brings together leaders to improve the security of open-source software.” The Foundation notes how pervasive open source has become, and how critical it is to bring together open-source security initiatives and those who support them to advance open-source security for all stakeholders. . Continuous Assurance and static analysis play crucial roles in enhancing open source security and ensuring compliance throughout the software development lifecycle. open source security, static analysis, cyber attacks, software compliance, Continuous Assurance. . Brittany Day
For the past two years, Intel CPUs have been under siege by an unending series of attacks that make it possible for cybercriminals to pluck passwords, encryption keys, and other secrets out of silicon-resident memory. New security research reveals that Intel's speculative execution flaws go deeper and are even harder to fix than we initially thought. . On Tuesday, two separate academic teams disclosed two new and distinctive exploits that pierce Intel’s Software Guard eXtension, by far the most sensitive region of the company’s processors. Abbreviated as SGX, the protection is designed to provide a Fort Knox of sorts for the safekeeping of encryption keys and other sensitive data even when the operating system or a virtual machine running on top is badly and maliciously compromised. SGX works by creating trusted execution environments that protect sensitive code and the data it works with from monitoring or tampering by anything else on the system. . Multiple groups disclose vulnerabilities aimed at AMD's SEV, endangering encryption integrity and safeguarding information.. Intel SGX Exploit, Cybersecurity Risks, Encryption Key Theft, Hardware Vulnerability. . Brittany Day
Each year a few hackers do something new that begs further examination. The general public and Hollywood paints most hackers as these uber-smart people who can take control of entire city’s infrastructure and crack any password in seconds.. The reality is that most hackers are fairly average people with average intelligence. Most don’t do anything new. They just repeat the same things that have worked for years, if not decades, using someone else’s tool based on someone else’s hack from many years ago. The link for this article located at CSO Online is no longer available. . The high-profile cyber hacks of 2018 exposed vulnerabilities in organizations, revealing techniques like social engineering and outdated security measures.. Hacker Insights, Cyber Attacks 2018, Security Trends, Hacking Behaviors. . LinuxSecurity.com Team
The US Department of Justice (DOJ) today unsealed indictments against a pair of Chinese agents charged with hacking US computer systems from a period spanning 2006 – 2018. Among those successfully targeted was the US Navy. . Personally identifiable information including, social security numbers, names, and phone numbers pertaining to at least 100,000 US Navy service members was allegedly stolen during the espionage campaign. The link for this article located at The Next Web is no longer available. . Covert operation compromised sensitive data of 100,000 Army personnel, underscores critical flaws in security protocols.. US Navy Hacking, Cybersecurity Breach, Personal Data Theft, Espionage Attack. . LinuxSecurity.com Team
British hacker Stephen Tomkinson has found two Blu-Ray-borne attacks. His first exploit relies on a poor Java implementation in a product called PowerDVD from CyberLink. PowerDVD plays DVDs on PCs and creates menus using Java, but the way Oracle's code has been used allows naughty folk to circumvent Windows security controls.. The result, the NCC Group consultant says, is that it's possible to put executables onto Blu-Ray disks and to make those disks run automatically on startup even when Windows is set to stop that outcome. Users would have no reason to suspect the whirring of an optical drive indicated unknown software was running, making this a potentially nasty attack. The link for this article located at The Register UK is no longer available. . The result, the NCC Group consultant says, is that it's possible to put executables onto Blu-Ray dis. british, hacker, stephen, tomkinson, found, blu-ray-borne, attacks, first, exploit, relies. . LinuxSecurity.com Team
An elite group of nation-state hackers running roughshod through the financial sector and other industries in the U.S. has pioneered techniques that others are following, and has used sophisticated methods to go after hardened targets, including hacking a security firm to undermine the security service the company provided its clients.. The highly professional group, dubbed Hidden Lynx, has been active since at least 2009, according to security firm Symantec, which has been tracking the group for some time. Hidden Lynx regularly uses zero-day exploits to bypass countermeasures they encounter. And, unusually for a government-sponsored effort, the gang appears to have a sideline staging financially motivated attacks against Chinese gamers and file-sharers. The link for this article located at Wired is no longer available. . A specialized team of state-sponsored cyber operatives infiltrates economic systems and employs advanced techniques to breach protective measures.. Hidden Lynx, State-Sponsored Hacking, Financial Cyber Threats. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.