By using this site, you agree to the Privacy Policy and Terms of Use.
Accept

Tec Informer

Tech news, Tips, tutorials , health tips and job circular

  • Latest
  • Mobile
  • Gadgets
  • Internet
  • Virtual reality
  • Artificial intelligence
  • Computing
Search here
Notification Show More
Aa
Aa

Tec Informer

Tech news, Tips, tutorials , health tips and job circular

Search here
  • Latest
  • Mobile
  • Gadgets
  • Internet
  • Virtual reality
  • Artificial intelligence
  • Computing
Follow US
2023 © TECINFORMER All Rights Reserved
Tec Informer > Tech News > Chinese hackers are exploiting a new Linux backdoor to target national governments -TECINFORMER
Tech News

Chinese hackers are exploiting a new Linux backdoor to target national governments -TECINFORMER

Tecinformer
Last updated: 2023/09/19 at 8:17 AM
Tecinformer
Share
2 Min Read
Malware
SHARE

Contents
Stealing files and moreMore from TechRadar Pro

A Chinese threat actor was observed targeting multiple governments around the world with a new Linux backdoor, according to new findings from Trend Micro.

As reported by BleepingComputer, the group is called Earth Lusca, and has been active in the first half of the year, targeting government organizations in Southeast Asia, Central Asia, the Balkans, and elsewhere. The organizations were mostly focused on foreign affairs, technology, and telecommunications. Earth Lusca’s goal seems to be espionage.

To compromise their targets’ endpoints, the group used multiple n-day unauthenticated remote code execution flaws, most of which were discovered and addressed between 2019 and 2022. Through these flaws, they’d drop Cobalt Strike beacons, which were later used to deploy a new Linux backdoor called SprySOCKS.

Table of Contents

  • Stealing files and more
    • More from TechRadar Pro

Stealing files and more

SprySOCKS is not brand new, though. Its code is a mix of multiple other malware variants, it was said, including the Trochilus open-source malware for Windows, a backdoor for the same OS called RedLeaves, and Derusbi, which is a Linux malware. 

Its key functionalities include system information harvesting, starting an interactive shell using the PTY subsystem, listing network connections, managing SOCKS proxy configurations, as well as the usual capabilities such as uploading and downloading files. 

Besides SprySOCKS, the group was seen dropping a Linux ELF injector dubbed “mandibule”, as well. Mandible itself was tweaked and changed, but in a relatively sloppy manner, it seems, as researchers found debug messages and symbols behind, indicating that the developers weren’t really paying attention that much. 

SprySOCKS, on the other hand, is in active development, the researchers concluded. So far, they managed to obtain two versions of the backdoor, including v1.1 and v.1.3.6. 

The best way to protect against such threats is to make sure all endpoints are patched regularly.

More from TechRadar Pro

Read the full article here

Share This Article
Facebook Twitter Copy Link Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

You Might Also Like

Here are the laptops to buy over the Surface Laptop Go 3
Tech News

Here are the laptops to buy over the Surface Laptop Go 3 -TECINFORMER

October 4, 2023
cyber, attack, hacked word on screen binary code display, hacker
Tech News

North Korean hackers are targeting aerospace – Lazarus Group tricks employees into installing malware themselves -TECINFORMER

October 4, 2023
This Microsoft Office deal gets you a lifetime license for just $33, also Windows 11 Pro for $29
Tech News

This Microsoft Office deal gets you a lifetime license for just $33, also Windows 11 Pro for $29 -TECINFORMER

October 4, 2023
OnePlus 11
Tech News

OnePlus says it’s made the best foldable phone so far – here’s why it might be right -TECINFORMER

October 4, 2023
Follow US
2023 © TECINFORMER All Rights Reserved
  • Disclaimer
  • Terms
  • Contact Us
  • About us
Go to mobile version
adbanner
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Lost your password?