New ultra-stealthy Linux backdoor isn’t your everyday malware discovery
arstechnica.com
arstechnica.com
Nothing here looks special, there are a plenty of these:
https://github.com/chokepoint/Jynx2
https://github.com/chokepoint/jynxkit
https://github.com/NexusBots/Umbreon-Rootkit
https://github.com/chokepoint/azazel
https://github.com/unix-thrust/beurk
https://github.com/mempodippy/vlany
https://github.com/nopn0p/rkorova
And presumably tens more I've forgotten about. Highschoolers write stuff like this.
``` for f in /proc/*/environ ; do sudo strings $f | >/dev/null grep LD_PRELOAD && echo $f; done ```
2. I'd suggest against using `strings` (let alone with sudo) on attacker controlled inputs
#include <stdio.h>
#include <stdlib.h>
static void begin() __attribute__((constructor));
void begin() {
unsetenv("LD_PRELOAD");
}
Build with: gcc -shared -fpie -o library.so library.c
Test: LD_PRELOAD=~/library.so env | grep LD_PRELOADUnless the ld_preload patches the process you are using to read the maps file, and gives you a false maps file.
However, on my Fedora 36 machine at least, it doesn't do so by default and I'd have to specify the `-d` flag for it to do this.
• libinput-gestures has spawned a /usr/lib/libinput/libinput-debug-events process with LD_PRELOAD=/usr/lib/coreutils/libstdbuf.so
• Firefox has spawned many /opt/firefox-nightly/firefox-bin processes with LD_PRELOAD=libmozsandbox.so
LD_PRELOAD=libmozsandbox.soRemoving it would just mean it gets hidden from the 'good guys' as well.
Most companies modify their detection rules because generic rules tend to cause false positives that could potentially overwhelm the SOC (security operations center). It really depends on your environment a lot.
My guess is the suppression held back the tide of Windows malware a year or two, but also gave MSFT a few years of fat, dumb and happy ignorance. Nimda, Code Red, Word macro viruses, etc hit Windows hard. If jokey small threats had been as available as they are today, MSFT might have been able to ramp up rather than get buried.
Sad state of affairs when people routinely ask for more censorship on what was supposed to be the freest technology to ever exist.
Since Linux is open source, how about not only “allowing” things like this to stay up, but encouraging everyone know about them?
I did this and it passed every anti virus on virustotal. I could have wrote the virus myself in a weekend but I thought it was funny that anti virus can't detect a virus thats modified ever so slightly I think we just need a better way of scanning for this stuff.
You train like you fight, you can't do research and build detections if you don't have some examples.
It seems all the old Windows techniques are now recycled on Linux.
Yeah, that's a straight up lie. LD_PRELOAD kits are by definition very easy to detect.
And disclosed in a blog post, with Nearly-Impossible-to-Read text.
It won't work on static binaries, it depends on the user not clearing the environment and there are also many programs that use the syscall directly, bypassing the hooks. From playing with file system hooks I remember programs written in Go and sqlite used to do this.
I also highly doubt "many" programs make syscalls directly, but I could be wrong. I know I haven't done so since the days I dabbled in assembly, at least.
All the important stuff you’d need to ruin someone’s life only needs their user account anyway, why is it such a relief if someone doesn’t get root access?
> Instead of being a standalone executable file that is run to infect a machine, it is a shared object (SO) library that is loaded into all running processes using LD_PRELOAD (T1574.006), and parasitically infects the machine. Once it has infected all the running processes, it provides the threat actor with rootkit functionality, the ability to harvest credentials, and remote access capability.
Also, if it just ruins a user account, you can simply delete that user's $HOME and restore their account from backups. If it elevates to root, you have to reformat the system and reinstall the whole OS from scratch (and hope it didn't patch the BIOS and/or hard disk firmware), and then reinstall all the user accounts from backups. Even if it's a single-user system, the non-root case is a lot less work to fix.
Pretty much all today's systems, either personal or server, are single user.
But most linux services run under their own user identities, so even in that case you will likely have several if not dozens of users on a typical server, the idea being that if the "nginx" user is compromised, the "postgres" user is still safe. Also why it was a bad idea to have services running as "root" (or "system") as was more common a decade or two ago.
Not everyone can afford a laptop per family member.
edit: and another comment linked to a blog post which also explains how this specific malware gains root https://www.intezer.com/blog/research/new-linux-threat-symbi...
> This process requires that the SO has the setuid permission flag set.
so you don't just have to download a binary file and somehow set LD_PRELOAD for that user, you also have to set the SUID bit on that binary file, which by itself only root can do...
My password manager requires my yubikey to be present, it's pincode to be entered and it to be touched for every use (to avoid remote hijacking). And I don't keep important things logged in.
But xkcd in this case also forgets that the reason for the admin accounts being separate is that most of the usual activity running in the user context means that malware runs in that context too. So it has a much harder time to obtain true persistence and undetectability like this exploit does.
Are you sure your passwords/session data can't be exfiltrated by other means, e.g. your .mozilla/.chromium?
>My password manager requires my yubikey to be present, it's pincode to be entered and it to be touched for every use (to avoid remote hijacking)
Going by KeepassXC docs, the database is encrypted with an HMAC challenge response, changing only on DB save. But if you have the ability to copy the database file and the HMAC response in the same point of time as this malware does, the yubikey part is useless. What password manager are you using?
I use a GPG-based password manager (pass) so this is not the case. Each password is encrypted individually using the GPG key in the yubikey. I hate keepass (I have to use it at work because they're stupid). I recently wrote a whole essay on why KeePass is so behind the times to our leadership, I hope they will finally go for something that actually has centralised management and auditing. We've seen teams that have used the keepass filename as master password for example and we have no way to prevent this kind of thing.
I also use Fido2 where possible which is even better of course.
And yes stuff can be exfiltrated but websites such as facebook, dropbox etc are pretty well defended against session cookie theft these days.
I'm just saying there is still a very good reason for the admin account to be boxed off, despite the XKCD makes it seem useless.
So this is hiding network traffic from certain ports, which means that it should be easy enough to spot on spanports or netflow data
Are there any good tools which detect malware from analysing network traffic, either things like machines doing wide range attempts to connect on 137/139/445, or burte forcing on 22 etc, but also for more advanced searches for traffic like this?
I see plenty of companies selling end point protection, but that's not much use with the amount of blackboxes I have on my network.
tcpdump "tcp[13] & 2 != 0"
Yes, I'm aware malware could use UDP/ICMP. It could also domain-front on 443 and I'm not under any disillusion this adds meaningful resistance to malicious software; it's just interesting to observe.Malware could always bounce traffic off of a known host but that would move the needle in any case.
proc on /proc type proc (rw,nosuid,nodev,noexec,noatime,hidepid=invisible)After a while, in security, the blog posts, adverts, and scanners are the malware that's taking our time and money.
https://devblogs.microsoft.com/oldnewthing/20060508-22/?p=31...
Yes, this particular malware is boring.
However, exploits are only tangentially related to malware. Malware by itself can be interesting and worth discussing.
> for symbionte to take hold, it has to social engineer it's way into a system, with a person executing it.
This is an utterly stupid criticism, as it could be applied to almost all actually novel malware.
Ars fell for marketing speech from an AV company that has every reason to hype their discovery.
Phrack has tons of relevant content, Blackhatacademy has some (https://nets.ec/LD_Preload)
A quick google search also found this simple walkthrough https://fluxius.handgrep.se/2011/10/31/the-magic-of-ld_prelo...
A basic BPF filter isn't fancy or difficult to implement.
Also sniffing for suspicious packets on the potentially compromised machine?
"Let's see if this robot is telling the truth. Hey robot, are you telling the truth?"