Researchers discovered a free download manager site that has been compromised to serve Linux malware to users for more than three years. . Researchers from Kaspersky discovered a free download manager site that has been compromised to serve Linux malware. While investigating a set of suspicious domains, the experts identified that the domain in question has a deb.fdmpkg[.]org subdomain. Visiting the subdomain with the browser, the researchers noticed a page claiming that the domain is hosting a Linux Debian repository of software named ‘Free Download Manager’. This package turned out to contain an infected postinst script that is executed upon installation. This script drops two ELF files to the paths /var/tmp/crond and /var/tmp/bs. It then establishes persistence by creating a cron task (stored in the file /etc/cron.d/collect) that launches the /var/tmp/crond file every 10 minutes.” reported Kasperksy. The “Free Download Manager” version installed by the malicious package was released on January 24, 2020. The experts found comments in Russian and Ukrainian, including information about improvements made to the malware, in the postinst script. . Cybersecurity analysts from Kaspersky have revealed a prolonged breach lasting three years that distributed Linux malware through a hacked download manager platform.. Linux Malware Threats, Backdoor Exploits, Compromised Software, Security Risks. . LinuxSecurity.com Team
We do not often talk about Linux malware because it is often quickly patched up and not exploited much in the wild compared to Windows/macOS. However, there has been a concern regarding the Free Download Manager (a decently popular cross-platform download manager). . While we do not recommend it on our available for Linux, some of our readers have suggested it in the past. And I have used it as well up until now on Windows. So, what is the issue? Free Download Manager is not malware . However, a malicious package for Linux was found, distributed as Free Download Manager. Security researchers at Kaspersky discovered that it existed for at least two years ( 2020-2022 ) without users knowing what they were installing. . Uncover the issues related to Free Download Manager and the potential threats posed by malware for Linux users. Keep yourself updated!. Linux Malware, Security Issue, Download Manager, Cyber Threats, User Concerns. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.