Explore top 10 tips to secure your open-source projects now. Read More
×The Nood RAT malware is a new threat to Linux servers worldwide. Security researchers say Nood RAT is designed to steal sensitive information from targeted servers. This article warns Linux admins and infosec professionals of the risks posed by the malware and how to prevent such cyberattacks. . How Does Nood RAT Malware Threaten Linux Servers? Nood RAT is a variant of the Gh0st RAT malware. Gh0st RAT for Windows is well-known and has been circulating for over a decade; however, this is one of the first Gh0st RAT strains to target Linux systems. Like its Windows counterpart, Nood RAT is a backdoor malware that can perform malicious operations such as downloading harmful files, stealing internal system files, and executing commands. Nood RAT has an encryption function that can evade network packet identification, which can be concerning for Linux admins and infosec professionals tasked with detecting and preventing such attacks. Additionally, the malware can receive commands from its threat actors and execute various harmful operations, putting sensitive data at risk of theft. Nood RAT can also impersonate itself as an authentic program and that threat actors can choose the malware's fake process name during its development phase. This makes detection more challenging, and it's a task that requires vigilance on the part of an organization's security team. The Chinese C. Rufus Security Team is the developer of Gh0st RAT and that its source code is available to the public. As a result, hackers have been using it in their attacks. In the case of Nood RAT, threat actors exploit the codes to create malware variations, putting Linux servers worldwide at risk of data theft. How Can I Protect Against Nood RAT? There are various measures that security practitioners can take to protect against Nood RAT. Investing in an Endpoint Detection and Response (EDR) solution that provides threat hunting and incident response capabilities can help detect and prevent malware attacks like Nood RAT. Linuxusers must keep their systems updated with the latest security patches and examine their environment configuration to avoid such security concerns. It is essential to remain vigilant in the fight against cyber threats. Our Final Thoughts on Nood RAT: What Can We Learn? Nood RAT is a new threat to Linux servers, and its implications are severe. This article warns Linux admins, infosec professionals, and security practitioners that such attacks are becoming more frequent. However, by being vigilant, staying informed , and investing in the right security solutions, we can stay ahead of cybercriminals and protect critical data from being stolen or compromised. . Nood RAT aims at Linux systems, introducing significant dangers. Remain updated to safeguard confidential information against digital attacks.. Nood RAT, Linux Malware, Cybersecurity Threats, Data Protection, Endpoint Security. . Brittany Day
ExaTrack, a France-based cybersecurity firm, has discovered a “novel” malware, which they have named Mélofée. According to the researchers, this malware is specifically targeting Linux servers and is believed to be operated by an unidentified Chinese state-backed APT group . . The researchers have linked this malware to the notorious Winnti group with high confidence. “We linked with high confidence this malware to Chinese state-sponsored APT groups, in particular the notorious Winnti group,” researchers said in a blog post . According to THN’s report, the malware has also been linked to another state-sponsored APT group called Earth Berberoka (or GamblingPuppet), which mainly targets gambling websites in China and has been active since 2020. The group uses multi-platform malware such as Pupy RAT and HelloBot. The malware’s capabilities include a kernel-mode rootkit, which is based on an open-source project called Reptile. The rootkit has limited features, as it mainly installs a hook designed to keep itself hidden. . Uncover the specifics of Sanctifex, the malicious software aimed at Linux systems associated with government-sponsored APT factions.. Mélofée Malware,Linux Threats,Cybersecurity Insights,APT Groups Analysis. . LinuxSecurity.com Team
Microsoft Defender for Linux - Microsoft's server-based Linux security program - is now ready to protect your Linux servers, Windows desktops, and Macs with endpoint detection and response capabilities. . After months in the making, Microsoft Defender for Endpoint on Linux server now has endpoint detection and response (EDR) abilities . I know. It's still startling but Microsoft now produces Linux security programs. Will miracles never cease? Now, this is not Microsoft Defender for the Linux desktop. Some miracles haven't happened yet. In this version of Defender, its No. 1 job is to protect Linux servers from server and network threats. If you want protection for your standalone Linux desktop, use such programs as ClamAV or Sophos Antivirus for Linux. With the new EDR features, you can also use it to protect PCs running macOS, Windows 8.1, and Windows 10 . . Microsoft Defender for Endpoint on Linux has introduced upgraded threat detection features, significantly bolstering server protection.. Microsoft Defender, Linux Servers, Threat Protection, Endpoint Detection, Security Solutions. . LinuxSecurity.com Team
Rootkit.Linux.Snakso.a is designed to infect the Linux kernel version 2.6.32-5-amd64 and adds an iframe to all served web pages by the infected Linux server via the nginx proxy. . The malware appears to be in its development stages as the code is rather large (more than 500k, including debugging information) and Kaspersky noted that "some of the functions don The link for this article located at Toms Hardware is no longer available. . The malware appears to be in its development stages as the code is rather large (more than 500k, inc. linux, rootkit, snakso, designed, infect, kernel, version, 32-5-amd64. . LinuxSecurity.com Team
Some organizations consider taking the plunge off of big iron PBX platforms into IP telephony as being pretty daring, but that's nothing compared to what Sam Houston State University (SHSU) is doing. The south Texas school is boldly moving thousands of users off a Cisco VoIP platform to an open-source VoIP network based on Asterisk. . SHSU is in the process of moving its 6,000 students, faculty and staff off of Cisco CallManager IP PBXs and a legacy Nortel Meridian PBX over to Linux servers running Asterisk, which includes call processing, voicemail and PSTN gateway functionality. The driver for this project was cost, says Aaron Daniel, senior voice analyst at Sam Houston State University. "We thought that it will be more cost effective in the long run to go with an open source solution, because of the massive amounts of licensing fees required to keep the Cisco CallManager network up and running," says Daniel, who this week gave a presentation on his migration project at the VON show in Boston. The link for this article located at Network World is no longer available. . The University of Texas at Arlington shifts from proprietary Avaya systems to community-driven FreeSWITCH, improving budget sustainability.. Open Source Asterisk, VoIP Solutions, Cost Effective Telephony, Cisco Alternatives. . LinuxSecurity.com Team
Tested over three months at IBM’s Linux Test Integration Center (LTIC) by a seven-person team, the 87-page report [pdf] titled "Linux Security: exploring open source security for a Linux server environment" set out to test a wide range of open-source Linux products supported by IBM to see whether they could adequately protect a middleware environment. Only open source products were us . The answer to this question was a resounding "yes", backed up by detailed technical description of the specification and configuration of the systems used in the testbed. Where alternative products were available to do a similar job, the report makes technical comparisons and comes up with judgments on their respective merits. The link for this article located at TechWorld.com is no longer available. . The answer to this question was a resounding 'yes', backed up by detailed technical description of t. tested, three, months, ibm’s, linux, integration, center, (ltic), seven-person. . Benjamin D. Thomas
If you have used email at all you have seen spam: unsolicited and unwanted email. The way that email works means that it is very easy to send out bulk mailings at a very low cost. The cost is low because . . . . If you have used email at all you have seen spam: unsolicited and unwanted email. The way that email works means that it is very easy to send out bulk mailings at a very low cost. The cost is low because largely it is the receiver of the email that pays. If you read email on a dialup modem line or pay for your Internet connection, then in a real sense you are paying for the spam you get. Often it is difficult for ISPs to block spam to everyone. This is because the ISPs do not know which email items you want to receive and which ones you do not. The ISP cannot predict in advance what email you have an expectation of getting and from where. It would also be inappropriate for ISPs to screen the content of the messages. There would also be privacy issues. However, there are certain approaches that can be taken at the email server side. If you have recently installed Linux and are thinking of running your own email server, then you should carefully consider the problem of spam. The link for this article located at LinuxPlanet is no longer available. . Combat spam effectively in Linux email systems with strategies like SpamAssassin, DKIM, SPF, ClamAV, Postscreen, and user education to enhance security. Email Security, Linux Server, Spam Management, Email Filtering Techniques, Open Source Software. . LinuxSecurity.com Team
With proper setup and administration, viruses in Linux are the least of your worries, but you still need to worry about Windows clients that connect to your Linux servers. I have been looking at anti-virus programs, designed to run on Linux servers, that can keep viruses from infecting Windows clients on the networks I administer. . . .. With proper setup and administration, viruses in Linux are the least of your worries, but you still need to worry about Windows clients that connect to your Linux servers. I have been looking at anti-virus programs, designed to run on Linux servers, that can keep viruses from infecting Windows clients on the networks I administer. There are a growing number of companies and GNU Projects coming forward to provide Linux antivirus products. The Open Antivirus Project aims to provide open source solutions to multiple antivirus needs, including squid-vscan (virus scanning with squid), samba-vscan (on-access virus scanning with Samba), and VirusHammer (a standalone virus scanner to be run by end users). Many other features and projects are planned, like rescue disks and remote management. The Open Antivirus Project also has a project page at / Commercial products are becoming available in the mainstream for Linux. McAfee, Trendmicro, Panda Software, Sophos, and Central Command all have products for home Linux users as well as enterprise networks. The link for this article located at Newsforge is no longer available. . With proper setup and administration, viruses in Linux are the least of your worries, but you still . proper, setup, administration, viruses, linux, least, worries, still. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.