Linux Systems Under Attack By New RedXOR Malware
#1
Information 
Quote:Researchers have discovered a new backdoor targeting Linux systems, which they link back to the Winnti threat group.
 
The backdoor is called RedXOR – in part because its network data-encoding scheme is based on the XOR encryption algorithm, and in part because its samples were found on an old release of the Red Hat Enterprise Linux platform. The latter fact provides a clue that RedXOR is utilized in targeted attacks against legacy Linux systems, noted researchers.
 
The malware has various malicious capabilities, said researchers – from exfiltrating data to tunneling network traffic to another destination.
 
“The initial compromise in this campaign is not known but some common entry points to Linux environments are: Use of compromised credentials or by exploiting a vulnerability or misconfiguration,” Avigayil Mechtinger, security researcher with Intezer, told Threatpost. “It is also possible the initial compromise was via a different endpoint, meaning the threat actor laterally moved to a Linux machine where this malware was deployed.”

The samples were detected after being uploaded to VirusTotal from two different sources in Indonesia and Taiwan. Researchers told Threatpost that based on this, it is likely that at least two entities have discovered the malware in their environment. 

Read more: Linux Systems Under Attack By New RedXOR Malware | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Linux Systems Under Attack By New RedXOR Malware - by silversurfer - 12 March 21, 08:40

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Windows 11 may nag you now when your Mic...
Microsoft continue...harlan4096 — 09:57
Bitdefender 27.0.54.271
Bitdefender 27.0.5...harlan4096 — 08:36
360 Total Security 11.0.0.1240
11.0.0.1240 Sep 9,...harlan4096 — 08:02
Vivaldi 7.5 Build 3735.74
Vivaldi 7.5 Build ...harlan4096 — 08:00
Firefox for iOS will summarize web pages...
Mozilla has announ...harlan4096 — 07:59

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (38)fapedDow
avatar (48)pohudidere
avatar (48)rarinsWax
avatar (25)DianaBrown
avatar (38)eqiduseb
avatar (45)ThomasLYDAY
avatar (40)upakoExapy
avatar (49)skepwHug
avatar (38)RicardoGoase
avatar (42)Edwardgef
avatar (43)Denpokhew
avatar (35)azidony
avatar (40)maskbSleew

[-]
Online Staff
There are no staff members currently online.

>