OrBit: New Undetected Linux Threat Uses Unique Hijack of Execution Flow
intezer.com
intezer.com
If you can program, you can learn almost any concept in security with self study and a handful of good books. Marketing posts, such as these, often aren't very useful but sure look neat with all the basic blocks...
Also, there’s a reason the “hello world” malware posts are popular - the techniques they’re describing might have been known for years, but they’re practical and they work. Often their longevity is only due to their unfixable nature in exploiting a design flaw. So they’re useful not only from a practical standpoint but also an academic one of demonstrating a class of attack so pernicious that it can only be eliminated with a ground up redesign.
Perhaps it's installed through infected packages? Sabotaged repositories? Privilege escalation by `alias`ing `sudo`?
As far as I can gather, one cannot do GDB without recompiling with --gdb option if LD_PRELOAD were disabled at compile-time.
So no can do disabling LD_PRELOAD on Debian (much less be able to use libmusl on a Debian)
But it is not a good workaround for Nix thus making Nix a poor candidate for a reasonably secured production servers.
I am fairly confident that this rootkit would be detected by rkhunter, but possibly only when the adversary is logged into the machine, as the malware hides the pids and network ports associated with their ssh connection.