EvilGnome: Rare Malware Spying on Linux Desktop Users
intezer.com
intezer.com
I'm glad this is still considered malware in the Linux world at least, and not just "analytics"
My (unpopular) opinion is that GNOME should see what are the most used extensions, accept that people want those feature and bring those features into GNOME or make those official extension and not third party, so you at least control what most people would install.
Extensions work by monkey-patching and once you have a critical mass of them, you're guaranteed to run into some glitches where one monkey-patch messes up the other. I like the KDE approach more where features are actually baked into the DE. It's much easier to reproduce bugs and fix bugs that can depend on different features being enabled. Everyone benefits.
That's an understatement. GNOME is so notorious for removing features that I recall jokes on Slashdot 15 years ago about how the next version of GNOME will just have a giant "Do Stuff" button in the middle of the screen.
I am a KDE user and to be fair during KDE4 days ,Plasma had a maintainer with big ego that had a similar mentality with GNOME devs, we could not get a patch merged in to hide the Cachew thingy. Makes me wonder if all this GNOME vision of removing non default options is just one guy with big ego and lot of influence
> This implant is delivered in the form of a self-extracting archive shell script created with makeself
Though some people do tend to install stuff via "curl | sudo bash"... but i think this malware is the least of their concerns :-P
For example i'd trust an apt repository or pip package developed by -say- Blender developers, regardless of it being a 3rd party repository or delivered through pip.
I most certainly trust that there is no ill intent from them and that it didn't raise any flags during testing. But even if I believe they have the resources to audit everything I might be getting a newer and infected version.
And even if my trust of a programmer/entity is rock-solid it is hard to guard against their account being compromised, that is all it takes for most 3rd party sources.
There will probably be quite a few wake up-calls where this is exploited.
Would love if someone would chime in on the reality here.
So my guess is, they're targeting Redhat Desktop, because it's the most likely Linux desktop to be seen in the corporate space. My old university had RHEL client machines.
Maybe they're just trying to get ahead of the curve with this?
Edit: Also, lately there has been more noise from more governments about using Linux, so yeah, getting ahead of the curve.
I think Ubuntu changed their minds and went back to Xorg, also Wayland+GNOME Shell has the terrible issue where the shell crashes would bring down your session and you lose all your work.
Debian just switched to Wayland so in the fallowing months we will see the effects, it could be a new pulse audio situation where you will get a lot of "fixes" starting by removing Wayland.
Systemd, GNOME3, DBUS - they are essentially omnipresent on "modern" linuxes these days. The questionable safety that was provided by snowflake installs is evaporating fast.
This is an oversimplification. There is a sweet spot for security between monoculture and excessive fragmentation.
Most lesser-famous Linux distributions struggle to provide extensive and timely security updates (or provides no security fixes at all by doing only "rolling" releases that track upstream).
To provide security a skilled security team, as well as a large enough userbase is needed.
Linux Desktops are not very common, which leads to wonder if more uniformity can be a good thing.
(of course this issue with uniformity can also happen outside of security reasons - e.g. if all distros provide more or less the same experience then why bother with a small distro?)
Although it could be a diversion, I wonder if the mention of Rostov (a city curiously close to Crimea) has any significance.
Because it's virtually to buy a computer in the shops with a Linux Desktop pre-installed. Even online Dell manages to keep a Linux Desktop computer well hidden on their website.
> .. in the beginning of July, we discovered a new, fully undetected Linux backdoor implant ..
How does this “fully undetected Linux backdoor” get onto the Desktop in the first place, without the end-user explicitly downloading and installing this Linux “implant”.
> .. We have named the implant EvilGnome, for its disguise as a Gnome extension ..
Thanking you, so the “implant” disguises itself as a Gnome extension and resides on some third-party website.
> .. The malware is currently fully undetected across all major security solutions ..
So, the defect resides in the security solutions :]
many gnome-based distros (fedora, for example) ship with firefox and the "gnome extensions" plugin for firefox pre-installed. this extension allows you to install extensions directly into your shell from extensions.gnome.org just by clicking "install".
suppose an exploit was found that allows sources other than extensions.gnome.org to trigger the firefox plugin to install a shell extension.
seems much more likely now, doesn't it?
The main reason i am dismissive is because if you think this is a real threat then you'd have to also think anything you can run on your computer to be a real threat - which, IMO, is absurd and at that point you might as well turn off and throw your computer out of the window.