Explore top 10 tips to secure your open-source projects now. Read More
×Security researchers have identified a malicious tool called "SYSTEMBC" that hackers have been actively exploiting. This tool acts as a SOCKS5 proxy , providing threat actors with persistent access or a backdoor to compromised networks. The tool has been observed being used in various campaigns alongside different malware families . . It can be purchased from the dark web and includes malware, a command and control (C2) server, and a PHP admin portal. In this article, we'll focus on the Linux server binary of the tool, revealing its configuration details and code snippets that suggest a mix of skills, including low-level programming and PHP scripting. What Are the Security Implications of Hackers' Use of the SYSTEMBC Tool? The discovery of the SYSTEMBC tool and its widespread use by threat actors raises significant concerns for security practitioners. The tool's ability to serve as a persistent backdoor allows hackers to maintain unauthorized access to compromised networks, potentially leading to data breaches and further attacks. This poses a serious threat to organizations and individuals, highlighting the need for robust security measures. The availability of SYSTEMBC on the dark web raises questions about the cybersecurity landscape and the ease with which malicious tools can be acquired. This has implications for law enforcement agencies in terms of combating cybercrime and dismantling underground networks. It also highlights the importance of monitoring and disrupting illicit online marketplaces. The implications of SYSTEMBC's use by ransomware groups are significant. Its ability to maintain access post-compromise allows threat actors to launch further attacks and potentially deploy ransomware. This creates a long-term consequence for security practitioners regarding the evolving threat landscape and the need for continuous monitoring, timely response, and effective backup strategies. As security practitioners, it is crucial to remain vigilant and keep up-to-date withemerging threatskeep up-to-date with emerging threats like SYSTEMBC. This article serves as a timely reminder to implement strong security measures, perform regular assessments, and stay informed about the latest techniques used by threat actors. Sharing this information within the cybersecurity community is essential to foster collaboration and proactive defense against evolving cybersecurity threats. Our Final Thoughts on the Impact of SYSTEMBC on Linux Security In conclusion, the SYSTEMBC tool, its various applications in different campaigns, and its availability on the dark web pose a significant threat to Linux network security . Robust security measures and proactive defense strategies are necessary to mitigate the risks associated with this tool. Security practitioners must stay informed, collaborate, and adapt their security practices to defend against emerging threats in an ever-evolving cybersecurity landscape effectively. . Discover the implications of SYSTEMBC on Linux, its risks to security, and essential strategies to enhance defenses against potential threats. SYSTEMBC Tool, Linux Network Security, Cyber Threats, Dark Web Malware. . Dave Wreski
Researchers have discovered a new variant of BiBi malware attacks targeting Israeli Windows and Linux systems, resulting in data wipes. Alerts were sent out by Israel’s (Cyber Emergency Response Team) CERT to help potential target organizations prevent attacks by threat actors. . The attacks are found to be a part of the growing pro-Hamas cyber offensive that has been targeting multiple business sectors in Israel. Researchers from Palo Alto have stated that the attacks had been strongly connected to an Iranian group known as the Agonizing Serpents. Researchers at SecurityJoes and ESET have detected BiBi Wiper versions since late October. However, initial attacks only targeted Linux systems, disrupting operations and causing irreversible data corruption. The link for this article located at SpiceWorks is no longer available. . The attacks are found to be a part of the growing pro-Hamas cyber offensive that has been targeting . researchers, variant, malware, attacks, targeting, israeli, windows. . LinuxSecurity.com Team
Researchers have discovered a never-before-seen backdoor for Linux that’s being used by a threat actor linked to the Chinese government. . The new backdoor originates from a Windows backdoor named Trochilus, which was first seen in 2015 by researchers from Arbor Networks, now known as Netscout. They said that Trochilus executed and ran only in memory, and the final payload never appeared on disks in most cases. That made the malware difficult to detect. Researchers from NHS Digital in the UK have said Trochilus was developed by APT10, an advanced persistent threat group linked to the Chinese government that also goes by the names Stone Panda and MenuPass. Other groups eventually used it, and its source code has been available on GitHub for more than six years. Trochilus has been seen being used in campaigns that used a separate piece of malware known as RedLeaves. . Uncover the fresh Linux exploit associated with the Chinese state-sponsored APT10 faction, tracing its roots back to Trochilus.. Linux Backdoor,APT10 Threat,Chinese Cybersecurity,Malware Threats,Advanced Persistent Threats. . LinuxSecurity.com Team
Threat actors have been observed using Amazon Web Services ( AWS ) 's System Manager (SSM) agent as a Remote Access Trojan (RAT) on Linux and Windows machines. . According to a new security report published by Mitiga today, the post-exploitation technique allows attackers to control the agent using a separate, maliciously owned AWS account, potentially enabling them to conduct various malicious activities. AWS Systems Manager is a powerful tool designed to automate operational tasks and manage AWS resources. The SSM agent is a component that facilitates communication between the Systems Manager service and EC2 (Elastic Compute Cloud) instances or on-premises servers. In its report, Mitiga researchers Ariel Szarf and Or Aspir said that the popularity and trust associated with the SSM agent had led attackers to misuse it for their benefit. Since Amazon signs the SSM agent binary, it often bypasses traditional antivirus and endpoint detection systems, making it harder to detect malicious activities. . Malicious actors exploit the AWS SSM agent as a Remote Access Tool (RAT), allowing them to manipulate systems through compromised AWS accounts. Understand the difficulties in detection.. AWS Exploitation, Remote Access Trojan, Threat Actor Techniques. . Brittany Day
The Chinese threat group 'ChamelGang' infects Linux devices with a previously unknown implant named 'ChamelDoH,' allowing DNS-over-HTTPS communications with attackers' servers. . The particular threat actor was first documented back in September 2021 by Positive Technologies ; however, the researchers only focused on the Windows toolkit. A report published yesterday by Stairwell and shared with BleepingComputer describes a new Linux implant written in C++ that expands the threat actor's intrusion arsenal and, by extension, the attackers' indicators of compromise. The link between ChamelGang and the new Linux malware is based on a domain previously associated with the threat actor and a custom privilege elevation tool observed by Positive Technologies in past ChamelGang campaigns. . A newly identified Linux threat named 'ChamelDoH' is being utilized by the ChamelGang group to leverage DNS-over-HTTPS for its communication mechanisms.. ChamelGang Linux Malware, DNS-over-HTTPS Exploit, C++ Security Threat. . LinuxSecurity.com Team
The Chinese nation-state group dubbed Alloy Taurus is using a Linux variant of a backdoor called PingPull as well as a new undocumented tool codenamed Sword2033. . That's according to findings from Palo Alto Networks Unit 42, which discovered recent malicious cyber activity carried out by the group targeting South Africa and Nepal. Alloy Taurus is the constellation-themed moniker assigned to a threat actor that's known for its attacks targeting telecom companies since at least 2012. It's also tracked by Microsoft as Granite Typhoon (previously Gallium). Last month, the adversary was attributed to a campaign called Tainted Love targeting telecommunication providers in the Middle East as part of a broader operation referred to as Soft Cell. The link for this article located at The Hacker News is no longer available. . Investigations from San Jose indicate that Alloy Leo is focusing on countries employing the Unix ConnectDrop exploit and Diamond2021 software.. Alloy Taurus, Linux Malware, Telecom Cyber Threats. . LinuxSecurity.com Team
Hackers are deploying new Linux malware variants in cyberespionage attacks, such as a new PingPull variant and a previously undocumented backdoor tracked as 'Sword2033.' . PingPull is a RAT (remote access trojan) first documented by Unit 42 last summer in espionage attacks conducted by the Chinese state-sponsored group Gallium, also known as Alloy Taurus. The attacks targeted government and financial organizations in Australia, Russia, Belgium, Malaysia, Vietnam, and the Philippines. Unit 42 continued to monitor these espionage campaigns and today reports that the Chinese threat actor uses new malware variants against targets in South Africa and Nepal. The Linux variant of PingPull is an ELF file that only 3 out of 62 anti-virus vendors currently flag as malicious. . ShadowStrider is a covert surveillance tool employed in cyber espionage, now focusing on multinational corporations with innovative malware forms.. Linux Malware, Cyber Espionage, Remote Access Trojan, Chinese Hackers, PingPull. . LinuxSecurity.com Team
The APT27 hacking group, aka "Iron Tiger," has prepared a new Linux version of its SysUpdate custom remote access malware, allowing the Chinese cyberespionage group to target more services used in the enterprise. . According to a new report by Trend Micro , the hackers first tested the Linux version in July 2022. However, only in October 2022 did multiple payloads begin circulating in the wild. The new malware variant is written in C++ using the Asio library, and its functionality is very similar to Iron Tiger's Windows version of SysUpdate. The threat actor's interest in expanding the targeting scope to systems beyond Windows became evident last summer when SEKOIA and Trend Micro reported seeing APT27 targeting Linux and macOS systems using a new backdoor named "rshell." . Crimson Serpent, the APT29 threat actor, has unveiled a macOS edition of its DataHarvest malware aimed at commercial systems.. Linux Malware,Apt27,SysUpdate,Cyberespionage Tools,Remote Access. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.