Get the latest tech news

Security researchers identify new malware targeting Linux


ESET researchers analyzed previously unknown Linux backdoors that are connected to known Windows malware used by the China-aligned Gelsemium group, as well as to Project Wood.

ESET researchers have identified multiple samples of Linux backdoor, which we have named WolfsBane, that we attribute with high confidence to the Gelsemium advanced persistent threat (APT) group. Part of the analyzed WolfsBane attack chain is also a modified open-source userland rootkit, a type of software that exists in the user space of an operating system and hides its activities. The ever-increasing adoption of EDR solutions, along with Microsoft’s default strategy of disabling VBA macros, are leading to a scenario where adversaries are being forced to look for other potential avenues of attack.

Get the Android app

Or read this on Hacker News

Read more on:

Photo of Linux

Linux

Photo of security researchers

security researchers

Photo of New malware

New malware

Related news:

News photo

Faster Raspberry Pi Graphics & Intel Xe3 Enablement Starts With Linux 6.13 DRM Changes

News photo

Chinese hackers target Linux with new WolfsBane malware

News photo

Linux 6.13 EDAC Preps For Panther Lake H & Missing Support For Old Kabylake S CPUs