Linux maintainers were infected for 2 years by SSH-dwelling backdoor with huge reach

Discussion in 'other security issues & news' started by Malcontent, May 15, 2024.

  1. Malcontent

    Malcontent Registered Member

    Joined:
    Dec 30, 2005
    Posts:
    620
    Location:
    Cleveland, Ohio USA
    Linux maintainers were infected for 2 years by SSH-dwelling backdoor with huge reach

     
  2. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,694
    See also ESET article:
    Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency theft and financial gain
    14 May 2024 - by Marc-Etienne M.Léveillé
    https://www.welivesecurity.com/en/e...rvers-compromised-cryptotheft-financial-gain/

    Read there more for analysis with .pdf document.
     
  3. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,711
    Location:
    The Netherlands
    So much for Linux systems being way more secure. Turns out that you indeed need to protect them, just like you would with Windows. :blink:
     
  4. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,076
    Location:
    Canada
    It looks like credential stealing/stuffing is the root cause, since then the perpetrators can gain root access with authentic credentials to install the malware. This is where 2FA, stronger passwords with frequent changes, and not falling for phishing scams should help to avoid these attacks.
     
  5. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,711
    Location:
    The Netherlands
    Yes, but what about when malware is already running on Linux? Seems like you still need AV/EDR in order to spot this stuff. I'm guessing that these Linux servers simply aren't monitored for malware activity.
     
  6. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,076
    Location:
    Canada
    That seems to be the case here.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.