Get the latest tech news

Thousands of Linux systems infected by stealthy malware since 2021


The ability to remain installed and undetected makes Perfctl hard to fight.

Thousands of machines running Linux have been infected by a malware strain that’s notable for its stealth, the number of misconfigurations it can exploit, and the breadth of malicious activities it can perform, researchers reported Thursday. Two such techniques are (1) modifying the ~/.profile script, which sets up the environment during user login so the malware loads ahead of legitimate workloads expected to run on the server and (2) copying itself from memory to multiple disk locations. From there, the file establishes a local command-and-control process and attempts to gain root system rights by exploiting CVE-2021-4043, a privilege-escalation vulnerability that was patched in 2021 in Gpac, a widely used open source multimedia framework.

Get the Android app

Or read this on ArsTechnica

Read more on:

Photo of Linux

Linux

Photo of Thousands

Thousands

Photo of Linux systems

Linux systems

Related news:

News photo

Linux 6.12 Drops New Driver That Ended Up Breaking Laptop Touchpad Support For Many Users

News photo

Golang Now Enables Speedier getrandom() On Linux

News photo

India: Police detain 600 striking Samsung workers at protest | Thousands of employees of the South Korean company have been on strike since September 9. They are demanding better wages, 8-hour working days, and union recognition.