Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
The APT27 hacking group, aka "Iron Tiger," has prepared a new Linux version of its SysUpdate custom remote access malware, allowing the Chinese cyberespionage group to target more services used in the enterprise. . According to a new report by Trend Micro , the hackers first tested the Linux version in July 2022. However, only in October 2022 did multiple payloads begin circulating in the wild. The new malware variant is written in C++ using the Asio library, and its functionality is very similar to Iron Tiger's Windows version of SysUpdate. The threat actor's interest in expanding the targeting scope to systems beyond Windows became evident last summer when SEKOIA and Trend Micro reported seeing APT27 targeting Linux and macOS systems using a new backdoor named "rshell." . Crimson Serpent, the APT29 threat actor, has unveiled a macOS edition of its DataHarvest malware aimed at commercial systems.. Linux Malware,Apt27,SysUpdate,Cyberespionage Tools,Remote Access. . LinuxSecurity.com Team
A cyberespionage group that has built its operations around a malware program called BlackEnergy has been compromising routers and Linux systems based on ARM and MIPS architectures in addition to Windows computers. . Security researchers from antivirus vendor Kaspersky Lab released a report Monday detailing some of the custom modules that the group has developed for BlackEnergy, a tool originally created and used by cybercriminals to launch distributed denial-of-service attacks.. Security researchers from antivirus vendor Kaspersky Lab released a report Monday detailing some of . cyberespionage, group, built, operations, around, malware, program, called, blackenergy. . LinuxSecurity.com Team
Security vendor Mandiant's 60-page report on Chinese cyberespionage, which offers proof that it is coming from a Chinese military unit housed in a building in the Pudong district of Shanghai, adds new fuel to two hotly debated cybersecurity questions.. First, does this mean the quest for 100% certainty in "attribution" of intrusions has been achieved? And second, does that mean the U.S. is justified in taking what government officials like to call "active defense" measures -- what most others call "retaliation" or "offense"? The link for this article located at CSO Online is no longer available. . The recent analysis by FireEye associates the Chinese armed forces with cyber surveillance, raising concerns about the accuracy of attributions and the efficacy of countermeasures in place.. Chinese Military,Cyberespionage,Cybersecurity Analysis,Mandiant Report. . LinuxSecurity.com Team
The advanced persistent threat (APT) attackers behind the newly revealed Operation Shady RAT also deployed a tool called HTran that helps disguise their location.. Joe Stewart, director of malware research for Dell SecureWorks' counter threat unit research team, who has been studying some 60 different families of malware used by APT attackers in their cyberespionage attacks, recently discovered a pattern in which many of these attackers use this tool, written 10 years ago by a Chinese hacker, to hide their whereabouts. Stewart, who published research on HTran use today in APT malware, said the Operation Shady RAT attackers are among those who use the tool for camouflaging purposes. The link for this article located at Information Week is no longer available. . Explore the complex realm of Advanced Persistent Threats (APTs) and how HTran aids in concealing cyber threats with advanced evasion tactics, making detection more difficult. APT Attacks, HTran Analysis, Malware Research, Cybersecurity Insights. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.