FOSSlife · @FOSSlife
865 followers · 1026 posts · Server mastodon.fosslife.org

New Linux-focused malware identified by AT&T Cybersecurity researchers uses sophisticated approach to target endpoints and IoT devices fosslife.org/new-linux-focused

#Shikitega #RemoteControl #security #devices #IoT #cryptominer #malware #Linux

Last updated 2 years ago

Who Let The Dogs Out · @ashed
68 followers · 6578 posts · Server mastodon.ml

New Stealthy Shikitega Malware Targeting Linux Systems and IoT Devices

Once deployed on a targeted host, the attack chain downloads and executes the Metasploit's "Mettle" meterpreter to maximize control, exploits vulnerabilities to elevate its privileges, adds persistence on the host via crontab, and ultimately launches a cryptocurrency miner on infected devices.

The exact method by which the initial compromise is achieved remains unknown as yet, but what makes Shikitega evasive is its ability to download next-stage payloads from a command-and-control (C2) server and execute them directly in memory.

Privilege escalation is achieved by means of exploiting CVE-2021-4034 (aka PwnKit) and CVE-2021-3493, enabling the adversary to abuse the elevated permissions to fetch and execute the final stage shell scripts with root privileges to establish persistence and deploy the Monero crypto miner.

thehackernews.com/2022/09/new-

#Shikitega #iot #linux #malware

Last updated 2 years ago