Some interesting malware I found
bobbiechen.com
bobbiechen.com
You have an actor who has system level permissions that allowed creating and registering launchd scripts. A browser extension cannot do that by itself. You've stopped the obvious parts of this malware, and that's absolutely all.
This machine needs to be wiped. If you don't have backups - move critical files and media to a new machine, ideally running a different OS, or to a cloud service.
Then do a completely fresh install of the OS.
for ubuntu 21.04+, i'm aware of: - gnome-tracker-miner - gnome-thumbnailer (may require browsing in nautilus) - mlocate
at least the first two appear to be sandboxed, though unclear of the efficacy. any other services that you're aware of that would be automated vectors ?
If you're running a lot of "untrusted code from github", then the list of services you have enabled or disabled on your system isn't going to make a difference.
For someone who frequently runs untrusted code, I'd recommend learning any of:
1. qemu / virsh / how to quickly and efficiently spin up isolated VMs
2. ec2/GCP/digital ocean/any similar VPS provider
3. QubesOS https://www.qubes-os.org/
The first two options will be a more secure way to run untrusted code and provide actual protection. The 3rd has better usability, though isn't as secure.
Disabling local thumbnailing services... yeah, sure, do that, but don't expect it to really do much against "testing out untrusted code".
An AWS VM in the cloud I ssh into can't possibly snoop on another window I have open.
QubesOS on the other hand includes usability features like displaying graphical interfaces from VMs, clipboard sharing features, etc etc https://www.qubes-os.org/doc/gui/
These usability features increase attack surface, whether they're implemented on top of a Xen or KVM hypervisor.
My assumption for a local qemu setup is that the user wouldn't use things like 9p or display sharing, which I think means a smaller enough attack surface to make a difference.
i'm trying to understand (and minimize, if needed) the automated risks of having untrusted files *stored* locally, which would give me time to read them and develop a level of trust
fwiw, if i need to run something untrusted, i'm using #2 some, but mostly:
4. a 2nd (untrusted) machine running locally, which is beefier than my laptop and also used for benchmarking.
i've never seen any unusual behavior from it, but treat it as though it's compromisedNot to mention the intel management engine thing, wifi firmwares, etc.
I believe in the conspiracy theory that computers are now built with low security in mind, to make it easier to compromise by 3 letter agencies, as long as those 3 letters agencies are holding supremacy in the cyber weapon warfare.
This still enables a few rogue black hats to lockpick those vulnerabilities every once and then, until most of them are caught and neutralized (either sent to prison or forced to work for those agencies).
I object to this vague and incurable diagnosis as an everyday response. I don't enjoy this topic but I practice good hygeine, habits and backups.. keep the possibility in mind? sure, lets not be naive. Every time, destroy the hardware? no, just no
KnockKnock looks for malware like this rogue launchd service.
You use it to quickly check for the presence of some forms of malware. It can integrate with VirusTotal databases.
BlockBlock runs as a background process, and blocks installation of launchd services and kernel extensions. It displays a (rather technical) alert when something tries to install such features. Relatively lightweight.
I also use Little Snitch, from (unrelated) Objective Development:
https://www.obdev.at/products/littlesnitch/index.html
It's quite a bit more complicated, a firewall with a sophisticated user interface that blocks outgoing traffic by default. The alerts let you add rules to allow such traffic. It can generate a _lot_ of alerts as you gradually build up a set of rules that match your usual usage.
I've recently re-installed macOS from Recovery, and I was pleasantly surprised that Little Snitch wasn't often triggered as I went about using my Mac.
I wouldn't necessarily recommend blocking firewall like Little Snitch for usual users; they wouldn't be able to deal with all the alert noise. Like Windows Vista, all over again. But I've come to rely on it... ObjectiveSee has a similar, free tool, if you want to see what I mean.
I strongly recommend ObjectiveSee tools. They are free and (I believe) open source.
Seeing that they've made a whole host of privacy oriented tools surprised me a lot. I will be trying out a few of them.
Thanks for sharing.
This seems like something that the Chrome/Firefox security teams could explore changing. Have you considered opening tickets with them? It's possible that they are simply unaware of this behaviour.
Exactly. this is why I will never side with LTT's "adblock is piracy and hurts creators waaaa waaa" bullshit. Ads are more often than not malicious, using clickbait to get people to.. Click on them.
Since no one offers what I want in a way that gets them paid, I'll use the free method instead.
Another headstone to add to the Google graveyard
Agreed
Yet.
Get a large enough user base, and malware will follow, and that may be the reason Linux is still relatively free from malware. Despite advancements, normal people still don't run Linux. It's either IT people or people who had their IT friend/child/whatever install it for them.
With browser extensions being used as delivery platforms, it may not be long until it hits Linux as well. The same delivery method (using a user lauchd job) would work for a user systemd job.
I assume they fought with each other for control of the machine, but I rebooted it instead.
Try it - it's interesting, use a USB stick to boot it, and make sure to physically disconnect all hard drives.
I think they mostly just want to send spam emails.
ME: "What's so funny?"
Dan: "You see that? Take a closer look."
ME: "What am I even looking at?"
Dan: "Simple script I built to track bots trying to break into our Linux box (server). What you're watching is a metric fuck ton of Chinese and other bots trying to brute force the login."
He explained that any new server being connected to the internet, regardless of OS will be instantly attacked like you said. The server in question was only online for about 30 minutes and we were watching an endless stream of automated attacks from different bots. The failed login attempts were blocked after two attempts and the IP addresses logged for further review; but the bots would just respawn at different IP ranges and try again, it was pretty crazy.
It was a big eye opener for me. I had no idea it was that bad. Man, was I naïve!
Long story short, i had to access internet on unsecured windows 7 machines that was as dirty as a public restroom in a fair. i had to upload documents on multiple occasions and i managed to infect my media with all sorts of viruses.
i decided to "keep" then, maybe if someone is interested in testing out these in a vm or something,i would be glad to share
Relevant: "macOS persistence – Beyond the good ol' LaunchAgents": https://news.ycombinator.com/item?id=28498058
I imagine that would provide further insight, such as the files you inadvertently removed.