This fearsome new Linux malware will send a shudder down the spines of IT professionals

digital data lock on screen
(Image credit: Shutterstock)

A brand new Linux malware strain capable of different kinds of nasties has been detected, capable of abusing legitimate cloud services to stay hidden in plain sight.

Cybersecurity researchers from AT&T Alien Labs recently discovered the malware and named it Shikitega. It comes with a super tiny dropper (376 bytes), using a polymorphic encoder that gradually drops the payload. That means that the malware will download and execute one module at a time, making sure it stays hidden and persistent. 

The command & control (C2) server for the malware is hosted on a “known hosting service”, making it stealthier, it was said.

Abusing PwnKit

The researchers aren’t absolutely certain what the malware’s authors were trying to achieve. 

Shikitega is quite potent, as it can run on all kinds of Linux devices, and allows threat actors to control the webcam on the target endpoint, as well as steal credentials. On the other hand, it’s also capable of running XMRig, a known cryptojacker that mines the Monero cryptocurrency for the attackers. One can only speculate that the XMRig was added to make use of compromised devices that have no sensitive data to be stolen. 

The malware relies on two vulnerabilities, both patched months ago, to compromise the devices and achieve persistence. One is PwnKit (CVE-2021-4034), one of the more infamous vulnerabilities that went undetected for some 12 years, before finally being spotted and fixed earlier this year. The other one is CVE-2021-3493, discovered and patched more than a year ago (in April 2021). 

While there’s a fix for both these holes, the researchers are saying, many IT administrators are yet to apply them, especially when it comes to Internet of Things (IoT) devices. 

The researchers don’t yet know who the authors are, and are suggesting all Linux admins to keep their software up to date, install an antivirus and/or EDR on all endpoints, and make sure they back up their server files.

Via: Ars Technica

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Close up of the Linux penguin.
A new Linux backdoor is hitting US universities and governments
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
A white padlock on a dark digital background.
Developers targeted by malicious Microsoft VSCode extensions
China
Chinese hackers develop effective new hacking technique to go after business networks
Ransomware
Microsoft spies a new and worrying macOS malware strain
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Google Pixel 8a in aloe green showing
Google Pixel 9a benchmark link teases the performance of the upcoming mid-ranger
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 17 (game #1148)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 17 (game #379)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 17 (game #645)
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over