CronRAT malware hides behind February 31st
sansec.io
sansec.io
...after reading: but also because one entry has a valid "every 30 minutes" specification :) and the rest are only used for storage.
The actual malware uses the task name from these "never occurring crontab". The invalid date is just a kind of signature.
What's the entry point for such a RAT? Does it scan for vulns in the server and plant itself there, or what? Article is lacking explanation of how a Linux e-commerce backend actually gets comp'd.
For years I've heard people saying: "People is not as used as windows, that's why nobody is interested in writing virus for linux." Turns out that considering the number of "embedded" linux these days, linux is probably much more popular than any other OS. Consider android devices, smart tv, routers... all these are devices that are directly in touch with the end users. The fact that these have been nowhere near as annoying as windows devices is a testament to how seriously developers and vendors have been taking security and also a bit of luck and the heritage of some unix ideas.
Of course, most high profile linux use are on servers. So it is expected that these systems are preferred targets. But considering all that, if you look closely at how some linux users, distributors and vendors behave, it seems like they are in another world. Security is mostly ignored as if linux was somehow magically free from vulnerabilities simply because you're using a package manager and mostly no extra security action is taken.
Maybe linux users and sysadmins became lazy or lax for the long years of a perceived security calmness. They will probably need a few incidents before learning some lessons from the windows crowd.
Hum, thank-you but no. The lessons the Windows crowd learned are mostly bullshit, officialized due to people's helplessness and total lack of any reasonable alternative.
Linux people are very serious about things like supply-chain verification, auditable software, and machine activity monitoring. All actions with viable engineering principles and real impact, differently from the "you need to install an antivirus" insanity.
Some sysadmins, sure, but definitely not all. Seriously, there are a lot of CentOS/RHEL 6 and below or Debian 8 and below running PHP 5.x that are still live on the internet, with vulnerabilities and all that have been fixed in that specific version. Saying that all Linux-based people care about security is ignorant of one-click offerings from various hosting sites, and those who don't care if they're running Linux or Windows in the name of hosting a site.
1. The group you described (conscientious sysadmins)
and
2. IOT vendors throwing Linux on devices without thought to updates and security.
Windows is insecure because it's "shopping spree" method of software management is inherently unsafe. At least desktop Linux enforces integrity protection when you're downloading software from your package manager, and gives you sandboxing options (albeit not very good ones) to further mitigate security concerns. Failing that, it gives people the option of using ludicrously secure systems like Tails, Whonix and Qubes, which would really be impossible with how Windows is set up.
It looks like there has never been a real 31 February.