The Insidexpress
  • Business
  • Lifestyle
    • Fashion
    • Beauty
    • Home Decor
    • Home
    • Interior Design
    • Foods & Culinary
    • Dating & Relationships
    • Health
    • Pets & Animals
    • Spirituality
    • Sports & Athletics
    • Travel
  • Entertainment
    • Celebrities
    • Gaming
    • Movies
    • Music
    • TV
  • Financial
    • Loans
    • Insurance
    • Stocks
  • Industrial
    • Auto & Motor
    • Career
    • Education
    • CBD
    • Construction
    • Real Estate
    • eCommerce
    • Legal
    • Essay Writing
    • Gambling
    • Vaping
  • Technology
    • Digital Marketing
    • SEO
    • Cryptocurrency
    • Software
    • Metaverse
    • NFT
    • Web Design
    • WordPress
  • News
    • India
    • Basketball
    • Golf
    • Horse Racing
  • Business
  • Lifestyle
    • Fashion
    • Beauty
    • Home Decor
    • Home
    • Interior Design
    • Foods & Culinary
    • Dating & Relationships
    • Health
    • Pets & Animals
    • Spirituality
    • Sports & Athletics
    • Travel
  • Entertainment
    • Celebrities
    • Gaming
    • Movies
    • Music
    • TV
  • Financial
    • Loans
    • Insurance
    • Stocks
  • Industrial
    • Auto & Motor
    • Career
    • Education
    • CBD
    • Construction
    • Real Estate
    • eCommerce
    • Legal
    • Essay Writing
    • Gambling
    • Vaping
  • Technology
    • Digital Marketing
    • SEO
    • Cryptocurrency
    • Software
    • Metaverse
    • NFT
    • Web Design
    • WordPress
  • News
    • India
    • Basketball
    • Golf
    • Horse Racing
The Insidexpress is a centralized magazine for Lifestyle, Fashion, Beauty, DIY, Interior Design, Health, Relationships, Travel, HowTo & more.
The Insidexpress
  • Business
  • Lifestyle
    • Fashion
    • Beauty
    • Home Decor
    • Home
    • Interior Design
    • Foods & Culinary
    • Dating & Relationships
    • Health
    • Pets & Animals
    • Spirituality
    • Sports & Athletics
    • Travel
  • Entertainment
    • Celebrities
    • Gaming
    • Movies
    • Music
    • TV
  • Financial
    • Loans
    • Insurance
    • Stocks
  • Industrial
    • Auto & Motor
    • Career
    • Education
    • CBD
    • Construction
    • Real Estate
    • eCommerce
    • Legal
    • Essay Writing
    • Gambling
    • Vaping
  • Technology
    • Digital Marketing
    • SEO
    • Cryptocurrency
    • Software
    • Metaverse
    • NFT
    • Web Design
    • WordPress
  • News
    • India
    • Basketball
    • Golf
    • Horse Racing
  • Technology

Password-stealing Linux malware goes undetected for 3 years

  • September 13, 2023
  • 3 minute read
Total
0
Shares
0
0
0
0
0
0
0
Enlarge / A digital Trojan horse.

Getty Images | posteriori

A download site surreptitiously served Linux users malware that stole passwords and other sensitive information for more than three years until it finally went quiet, researchers said on Tuesday.

The site, freedownloadmanager[.]org, offered a benign version of a Linux offering known as the Free Download Manager. Starting in 2020, the same domain at times redirected users to the domain deb.fdmpkg[.]org, which served a malicious version of the app. The version available on the malicious domain contained a script that downloaded two executable files to the /var/tmp/crond and /var/tmp/bs file paths. The script then used the cron job scheduler to cause the file at /var/tmp/crond to launch every 10 minutes. With that, devices that had installed the booby-trapped version of Free Download Manager were permanently backdoored.

After accessing an IP address for the malicious domain, the backdoor launched a reverse shell that allowed the attackers to remotely control the infected device. Researchers from Kaspersky, the security firm that discovered the malware, then ran the backdoor on a lab device to observe how it behaved.

“This stealer collects data such as system information, browsing history, saved passwords, cryptocurrency wallet files, as well as credentials for cloud services (AWS, Google Cloud, Oracle Cloud Infrastructure, Azure),” the researchers wrote in a report Tuesday. “After collecting information from the infected machine, the stealer downloads an uploader binary from the C2 server, saving it to /var/tmp/atd. It then uses this binary to upload stealer execution results to the attackers’ infrastructure.”

The image below illustrates the infection chain.

The infection chain of trojanized versions of Free Download Manager.

Enlarge / The infection chain of trojanized versions of Free Download Manager.

Kaspersky

After searching social media posts that discussed Free Download Manager, the researchers found that some people who visited freedownloadmanager[.]org received a benign version of the app, while others were redirected to one of the following malicious domains that served the booby-trapped version.

Advertisement

  • 2c9bf1811ff428ef9ec999cc7544b43950947b0f.u.fdmpkg[.]org
  • c6d76b1748b67fbc21ab493281dd1c7a558e3047.u.fdmpkg[.]org
  • 0727bedf5c1f85f58337798a63812aa986448473.u.fdmpkg[.]org
  • c3a05f0dac05669765800471abc1fdaba15e3360.u.fdmpkg[.]org

It’s not clear why some visitors received the non-malicious version of the software and others were redirected to a malicious domain. The malicious redirects ended in 2022 for reasons that are unknown.

The backdoor is an updated version of malware tracked as Bew, which was published in 2014. Bew was one of the components used in an attack back in 2017. The stealer called by the backdoor was installed in a 2019 campaign after first exploiting a vulnerability in the Exim Mail Server.

“While the campaign is currently inactive,” the researchers wrote, referring to the recent incident, “this case of Free Download Manager demonstrates that it can be quite difficult to detect ongoing cyber attacks on Linux machines to the naked eye.” They added:

The malware observed in this campaign has been known since 2013. In addition, the implants turned out to be quite noisy, as demonstrated by multiple posts on social networks. According to our telemetry, victims of this campaign are located all over the world, including Brazil, China, Saudi Arabia and Russia. Given these facts, it may seem paradoxical that the malicious Free Download Manager package remained undetected for more than three years.

  • As opposed to Windows, Linux malware is much more rarely observed;
  • Infections with the malicious Debian package occurred with a degree of probability: some users received the infected package, while others ended up downloading the benign one;
  • Social network users discussing Free Download Manager issues did not suspect that they were caused by malware.I

The post offers a variety of file hashes and domain and IP addresses that people can use to indicate if they’ve been targeted or infected in the campaign, which the researchers suspect was a supply chain attack involving the benign version of Free Download Manager. The researchers said people running the freedownloadmanager[.]org site didn’t respond to messages notifying them of the campaign. They also didn’t respond to an inquiry for this post.

Publisher

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Share 0
Share 0
Share 0
Share 0
Related Topics
  • Linux
  • Malware
  • Passwordstealing
  • undetected
  • Years
The Insidexpress

You May Also Like
The Latest Predictions on GTA VI Casting: Betting in Full Swing
View Article
  • 2 min
  • Technology

The Latest Predictions on GTA VI Casting: Betting in Full Swing

  • December 6, 2023
Is Your Windows or Linux Device Vulnerable to the LogoFAIL Firmware Attack?
View Article
  • 3 min
  • Technology

Is Your Windows or Linux Device Vulnerable to the LogoFAIL Firmware Attack?

  • December 6, 2023
6 Predictions and Possibilities of AI and Blockchain
View Article
  • 3 min
  • Technology

6 Predictions and Possibilities of AI and Blockchain

  • December 6, 2023
Microsoft Enhances Copilot with OpenAI Upgrades for Supercharging
View Article
  • 2 min
  • Technology

Microsoft Enhances Copilot with OpenAI Upgrades for Supercharging

  • December 6, 2023
Elon Musk’s xAI startup aims to raise  billion
View Article
  • 2 min
  • Technology

Elon Musk’s xAI startup aims to raise $1 billion

  • December 6, 2023
AI Video Content: Runway Getty Partnership for High-Quality Videos
View Article
  • 2 min
  • Technology

AI Video Content: Runway Getty Partnership for High-Quality Videos

  • December 6, 2023
15 Essential Tips for Small Businesses to Choose the Right Finance Technology Solutions
View Article
  • 7 min
  • Technology

15 Essential Tips for Small Businesses to Choose the Right Finance Technology Solutions

  • December 6, 2023
Mark Zuckerberg Sells 5 Million of Meta Stock: Here’s What You Need to Know
View Article
  • 2 min
  • Technology

Mark Zuckerberg Sells $185 Million of Meta Stock: Here’s What You Need to Know

  • December 6, 2023
    • Health
    Top 9 Comforting Blankets for Improved Sleep – Outperforming a Baby’s Rest
    • Technology
    The Hidden Truth Behind YouTube’s Mysterious Rabbit Holes
    • Lifestyle
    A Beginner’s Guide to Enjoying Running: Tips for Getting Yourself Started
    • Lifestyle
    Kids Trapped in 29C Marquees as School Classrooms Close Due to Crumbling Concrete – 4 Week Duration
    • Gaming
    Stalker 2: Heart Of Chornobyl Preview – Promisingly Brutal
    • Sports & Athletics
    Gundogan Unveils Astonishing Efforts by John Stones to Secure Man City Captaincy
    • Business
    Privacy Protection- The Urgency to Cease Ad Tracking
    • Music
    This Record’s Showcased Fun-Filled Experience: Embracing Freedom
    • TV
    High Seas Adventures with Swashbuckling Pirate Samurai
    • Movies
    Why is Julian Sands in Harry Potter trending?
Featured Articles
  • Is Email Marketing Still Relevant in Today’s Digital Landscape?
    • 7 min
  • Crafting Unforgettable Experiences: Event Success with the 3 M’s
    • 18 min
  • Top Email Marketing Ideas for the 2023 Holiday Season
    • 7 min
About Insidexpress

The Insidexpress is a centralized magazine for Business, Lifestyle, Fashion, Beauty, Entertainment, Culture, Living, Travel, Health, How-To, Technology, World News & more.

Things you might like
  • Although the owner of gambling sites is not on gamstop UK www.newonline-casinos.co.uk, his sites are successful and attract players. They have many slot machines and live sections; you can enjoy bonuses, especially free spins for new and popular slot online
  • List of non uk casinos accepting uk players newukcasino.uk
  • Best bonuses at european casinos that accept uk players with big wins
  • Visit Best CSGO Gambling to gather the latest gambling guides.
  • We have the best-reviewed crypto casinos at CryptoCasinos.com
Recent Posts
  • Deal Or No Deal Viewers Raise £85,000 For Man With Life-Limiting Condition 1
    Deal Or No Deal Viewers Raise £85,000 For Man With Life-Limiting Condition
    • 06.12.23
    • 3 min
  • Release date confirmed for Amy Winehouse biopic “Back To Black” 2
    Release date confirmed for Amy Winehouse biopic “Back To Black”
    • 06.12.23
    • 2 min
  • Louis Walsh criticizes two X Factor winners in verbal attack 3
    Louis Walsh criticizes two X Factor winners in verbal attack
    • 06.12.23
    • 3 min
  • NewJeans’ Hanni Covers Sarah Kang’s ‘Once in a Moon’ – Listen Now 4
    NewJeans’ Hanni Covers Sarah Kang’s ‘Once in a Moon’ – Listen Now
    • 06.12.23
    • 2 min
The Insidexpress
  • Home
  • Contact Us

Input your search keywords and press Enter.