A new XZ backdoor scanner will be able to safeguard any Linux binary from threats

IT teams worried about the XZ Utils supply chain attack can breathe a bit more easily after Binarly released a free online scanner to ease worries.

Cybersecurity researchers looking into slow SSH logins on Debian Sid recently discovered a backdoor in the latest version of XZ Utils, a set of data compression tools and libraries, used by major Linux distros.

The backdoor leveraged a vulnerability tracked as CVE-2024-3094, and was introduced to XZ version 5.6.0 by a pseudonymous attacker, and it persisted in 5.6.1. Soon after its discovery, the cybersecurity community rallied to address the issue, with CISA suggesting downgrading the tool to 5.4.6. Stable, and then hunting for, and reporting, any malicious activity.

Better results

Other security teams started byte string matching, file hash blocklisting, and different YARA rules, all of which weren’t exceptionally effective. Some even led to false positives, which only made the problem worse.

Enter Binarly, with a dedicated scanner that works for the particular library, and any file with the same backdoor.

"Such a complex and professionally designed comprehensive implantation framework is not developed for a one-shot operation. It could already be deployed elsewhere or partially reused in other operations. That's exactly why we started focusing on more generic detection for this complex backdoor," Binarly said in its announcement.

Compared to previous methods, this scanner returns better results, it was said, as it scans for various supply chain points beyond just the XZ Utils project.

"This detection is based on behavioral analysis and can detect any variants automatically if a similar backdoor is implanted somewhere else," Binarly's lead security researcher and CEO, Alex Matrosov, told BleepingComputer. "Even after recompilation or code changes, we will detect it," Matrosov added. 

The scanner can be found at xz.fail.

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
coding
Popular open source vulnerability scanner Nuclei forced to patch worrying security flaw
Close up of the Linux penguin.
A new Linux backdoor is hitting US universities and governments
Representational image depecting cybersecurity protection
OpenSSH vulnerabilities could pose huge threat to businesses everywhere
A computer being guarded by cybersecurity.
Worrying Windows security issue patched by 7-Zip, so patch now
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Top file synchronization tool Rsync security flaws mean up to 660,000 servers possibly affected
Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does