Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Beware! A New Linux Malware From Russian Hackers Is Stealing Data
fossbytes.com ^ | By Anmol Sachdeva - August 14, 2020

Posted on 08/14/2020 12:16:42 PM PDT by Red Badger

he National Security Agency (NSA) and FBI have issued a warning against a new Linux malware dubbed “Drovorub” that is believed to have been developed by Russian military hackers.

According to a report based on data collected by the agencies, the Linux malware strain is the work of APT28, a notorious hacking group from military unity 26165 of the Russian General Staff Main Intelligence Directorate (GRU) 85th Main SpecialService Center (GTsSS). The intention behind spreading the malware is espionage and stealing secrets from the public sector and IT companies. Drovorub Linux Malware

Drovorub Linux malware, as per the two agencies, consists of an implant, a file transfer tool, a kernel module rootkit, a command and control server, and a port forwarding module. The report mentions that the malware is highly stealthy and can manage to stay undetected in machines owing to advanced rootkit technologies deployed by hackers. The stealthy capabilities of Drovorub Linux malware make it easy for hackers to target different types of platforms, initiating attacks at any time.

The report describes the functioning of each component of the Linux malware that communicates with each other using JSON over WebSockets and the traffic is encrypted from the server module using the RSA algorithm.

How to stay safe from Drovorub Linux Malware?

The NSA and FBI have enlisted a few precautionary measures that could be used to stay safe from the new strain of Linux malware:

Keep all Linux systems updated to kernel version 3.7 or later. Systems must be configured to load modules with digital signatures. Enable the UEFI Secure Boot verification mechanism.


TOPICS: Business/Economy; Computers/Internet; History; Military/Veterans
KEYWORDS:
Navigation: use the links below to view more comments.
first 1-2021-32 next last

1 posted on 08/14/2020 12:16:42 PM PDT by Red Badger
[ Post Reply | Private Reply | View Replies]

To: Swordmaker; ShadowAce

Linux ping!.............


2 posted on 08/14/2020 12:17:03 PM PDT by Red Badger (Jesus said "There is no marriage in Heaven." ... That's why they call it Heaven............)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

In Russia, data steals from you...


3 posted on 08/14/2020 12:21:42 PM PDT by HombreSecreto (The life of a repo man is always intense)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

so....this means what for my little Linux laptop that I use to read news and check email?


4 posted on 08/14/2020 12:22:16 PM PDT by Buckeye McFrog (Patrick Henry would have been an anti-vaxxer.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

wouldn’t you have to download something that contained it first? (I don’t know much abotu how viruses work- or infect- )


5 posted on 08/14/2020 12:22:27 PM PDT by Bob434
[ Post Reply | Private Reply | To 1 | View Replies]

To: rdb3

Ping!...............


6 posted on 08/14/2020 12:22:50 PM PDT by Red Badger (Jesus said "There is no marriage in Heaven." ... That's why they call it Heaven............)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Buckeye McFrog

Your little Linux Laptop is spying on you for Russia!.............


7 posted on 08/14/2020 12:23:58 PM PDT by Red Badger (Jesus said "There is no marriage in Heaven." ... That's why they call it Heaven............)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Bob434

Sometimes all you have to do is just go to a website and you’re infected........Or a e-mail from a friend or relative has it because they did..............


8 posted on 08/14/2020 12:24:58 PM PDT by Red Badger (Jesus said "There is no marriage in Heaven." ... That's why they call it Heaven............)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Red Badger

ok thanks-

Here’s a site that talks abotu how to ‘harden linux’ but it’s way above my capabilities- others might like to see it though?

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/on-drovorub-linux-kernel-security-best-practices/

Would be nice if we could run linux in a sandbox like environment, and delete the daily sessions every evening- I suppose virtualbox coudl do that- would have to look into that- how to get email in it- and not lose emails when session is deleted- (We’re very careful abotu our emails, but yup- others coudl send it- but we don’t open attachments unless we know it’s benign things like family photos or something)


9 posted on 08/14/2020 12:37:32 PM PDT by Bob434
[ Post Reply | Private Reply | To 8 | View Replies]

To: HombreSecreto

I can’t even enjoy Linux anymore.

Nothing is sacred.


10 posted on 08/14/2020 12:39:51 PM PDT by wally_bert (Transmission tone, Selma.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Red Badger

This is also a good way to get you to update your systems to the CIA kernel mod needed before election day. How would we know one way or the other?


11 posted on 08/14/2020 12:46:56 PM PDT by epluribus_2 (He, had the best mom - ever.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Red Badger

Lunix Malware?

12 posted on 08/14/2020 12:57:03 PM PDT by McGruff (Polls are for dancing)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger
Keep all Linux systems updated to kernel version 3.7 or later.

A lot of distros do a wretched job of keeping their kernel updated. For reference, kernel version 5.8 was just released. If you can, learn to build & install your own kernel.

13 posted on 08/14/2020 1:09:33 PM PDT by Campion (What part of "shall not be infringed" don't they understand?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Campion
uname -r

tells me 5.4.0-42-generic on Kubuntu 20.04

The NSA and FBI have been explicit in their report that systems with a kernel version of 3.7 or lower are most susceptible to Drovorub malware due to the absence of adequate kernel signing enforcement.

Some tips here on McAfee website. https://www.mcafee.com/blogs/other-blogs/mcafee-labs/on-drovorub-linux-kernel-security-best-practices/

14 posted on 08/14/2020 1:26:39 PM PDT by Pollard (whatever)
[ Post Reply | Private Reply | To 13 | View Replies]

To: Bob434

That’s ok neither do most public health directors.


15 posted on 08/14/2020 1:27:10 PM PDT by Polynikes ( Hakkaa paalle)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Pollard

That’s way better than 3.7 !


16 posted on 08/14/2020 1:28:49 PM PDT by Campion (What part of "shall not be infringed" don't they understand?)
[ Post Reply | Private Reply | To 14 | View Replies]

To: Red Badger
Sometimes all you have to do is just go to a website and you’re infected........Or a e-mail from a friend or relative has it because they did..............

It would have to be something that can escalate privs to root. In Linux, I don't know of any email programs that will auto-execute attachments. Attachments are generally saved with a filemask of 644 or 640, which will not execute natively.

17 posted on 08/14/2020 1:30:49 PM PDT by zeugma (Stop deluding yourself that America is still a free country.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: wally_bert

Linux used to be a small almost unknown operating system, and not worth hacking into.

That’s all changed.

Go find a small unknown system and all will be good again.


18 posted on 08/14/2020 2:29:25 PM PDT by Balding_Eagle ( The Great Wall of Trump ---- 100% sealing of the border. Coming soon.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Balding_Eagle

I toyed with Linux off and on.

Suse was my favorite back when it was young.


19 posted on 08/14/2020 2:33:42 PM PDT by wally_bert (Transmission tone, Selma.)
[ Post Reply | Private Reply | To 18 | View Replies]

To: Red Badger

Guess my DOS machine is safe...


20 posted on 08/14/2020 3:12:16 PM PDT by SuperLuminal (Where is Sam Adams now that we desperately need him)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-32 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson