Blog Layout

Beware Of New Backdoor Malware Targeting Linux Users

sccomputerguys • May 31, 2022

The name Kevin Beaumont may not be familiar to you, but if you're a Linux or Solaris user, he may have just saved you a whole lot of grief.

Recently, Mr. Beaumont discovered a stealthy backdoor malware that has been quietly infecting Linux and Solaris SPARC systems for more than five years.  BPFdoor only parses ICMP, UDP and TCP packets checking them for a specific data value and in the case of UDP and TCP packets, also checking for a password.

It can sit quietly on an infected system for an extended period. However,  once triggered, it allows the hacker who placed it there complete access to a compromised device.  Beaumont found BPDdoor activity on networks all over the world.  It was most notably found in South Korea, Hong Kong, India, Vietnam, Myanmar, Turkey and of course, the United States.

He also discovered eleven different speed test servers infected with BPFdoor. Although he was at a loss to explain how those systems may have been compromised since they run on closed-source software.

A different researcher named Craig Rowland issued a comprehensive technical report on BPFdoor and outlined some of its very clever anti-evasion tactics.

The tactics include the fact that it:

  • Resides in system memory and deploys anti-forensics action (wipes the process environment, albeit unsuccessfully as it leaves it empty)
  • Loads a Berkeley Packet Filter (BPF) sniffer allowing it to work in front of any locally running firewalls to see packets
  • Modifies 'iptables' rules when receiving a relevant packet to allow attacker communication through the local firewall
  • Masquerades the binary under a name like a common Linux system daemon
  • Renames and runs itself as /dev/shm/kdmtmpflush
  • Changes the date of the binary (time stamping) to October 30, 2008, before deleting it

Thanks to the research of these two individuals, an incredibly stealthy malware strain that specifically targets Linux and Solaris systems has now been exposed to sunlight.  Although the malware is well-designed and contains several clever anti-evasion tactics, now that the word is out, IT Security professionals know what to look for and can begin the process of purging it from infected systems.  Kudos to both.

By sccomputerguys 22 Jul, 2022
Do you own one or more of the following products made by Cisco? The RV110W Wireless-N VPN Firewall The RV130 VPN Router The RV130W Wireless-N Multifunction VPN Router The RV215W Wireless-N VPN ...
By sccomputerguys 21 Jul, 2022
Do you use Microsoft Teams?  If so, you'll be thrilled to know that the Redmond Giant is continuing to pour resources into improving the software with a specific focus on audio and ...
By sccomputerguys 20 Jul, 2022
Corporate branding can be worth its weight in gold and certain images are absolutely iconic.  The Golden Arches, the Nike "swoosh," and Apple's Apple all come to mind. Logo images give companies ...
By sccomputerguys 19 Jul, 2022
Remember the Heartbleed scare we had a couple years back?  It was a nasty side-channel attack that was somewhat exotic and difficult to pull off, and it was absolutely devastating and sent ...
By sccomputerguys 18 Jul, 2022
Microsoft Exchange servers are once more in the crosshairs of hackers around the world.  Most recently, hacking groups have been specifically targeting them to deploy BlackCat ransomware. As is common among ransomware ...
By sccomputerguys 16 Jul, 2022
If you grew up in the days before the internet, it's absolutely staggering to think of all the ways that mobile technology has changed our lives (and mostly for the better). Remember ...
By sccomputerguys 15 Jul, 2022
It may seem as though Internet Explorer is the browser that will not die, but according to Microsoft, it is now a step closer to breathing its last virtual breath. Microsoft has ...
By sccomputerguys 14 Jul, 2022
If you're involved with IT Security at any level and if your network includes Linux servers, keep a watchful eye out for the new Panchan botnet. It first appeared in the wilds ...
By sccomputerguys 13 Jul, 2022
These days, companies spend significant sums of money to protect themselves from cyber criminals.  The threat matrix is vast, and attacks can come from almost any quarter. That is why many companies ...
By sccomputerguys 12 Jul, 2022
Do you receive healthcare of any kind from Kaiser Permanente?  If so, be aware that they recently published a data breach notification indicating that an unidentified attacker accessed an email account that ...
More Posts
Share by: