Thousands of Linux systems infected by stealthy malware since 2021
arstechnica.com
arstechnica.com
Which is unfortunate, because all the windows nastys are comming to us, and Linux is woefully underprepared.
For all the damage antivirus does, it still delivers some value. And we need equivalents for that value, or the mcafees will take over by default.
Unfortunately for McAfee, Bitcoin did not reach $1 million by 2020. Unfortunately for us, he didn't eat his dick either.
half of the worlds money was printed in the first 90 days of that year.
you dont think that could had caused a FOMO panic too viral for the mainstream attention apparatus to handle?
they couldnt even handle the (incredibly obvious, glaring) gamestop fiasco; the price of BTC could had literally reached $10m in Jan2020 if the right cataclysm of media, social issue wedging, economic woes, political bile, macro-financial fuckery, and a globally-proliferated bio-weap had happened to all strike just in a closer timeframe.
Got any other grand predictions you want to make about crypto, while we're here?
An amalgamation of the glory days after gold, fiat, the internet, and before the proliferation of homomorphic encryption and zero knowledge proofs and their near-ungovernable utility.
This is all true, but it doesn't matter. He was the founder of McAfee software, and the company still bore his name. Even worse, they chose to keep his name as the company name, even though he was "an international pariah and violent criminal ringleader" as you say.
So why shouldn't I believe him when he says their software is garbage? A company that stupid can't possibly make good software. A smart company would have changed the name once their founder became infamous.
>Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. Dan is based in San Francisco. Follow him at @dangoodin on Mastodon. Contact him on Signal at DanArs.82.
With the credentials of the author being seemingly impeccable, how can his article be so bad?
> Using a Unix socket over TOR for external communications
This is being said under the implication of sophistication. Using TOR for exfiltration or C2 related activities is amateur as it obviously will be detected. A minimum standard in this category for malware is something that makes use of primary gadgets of trusted hosts like Google, Microsoft or Apple. A more sophisticated area of this are various abuses of DNS and other accepted protocols where data can be stuffed into "trusted" records by places like Cloudflare.
> Stopping activities that are easy to detect when a new user logs in
This and a few other "points" like this seem like filler. This has been a thing malware does since the beginning and is the most basic anti-detection "technique" possible.
> Manipulating the Linux process pcap_loop through a technique known as hooking to prevent admin tools from recording the malicious traffic
At least he mentions the specific thing being hooked here, but again, the idea that malware would override the system or an API in some way to lie to the rest of the system is one of the most fundamental things a malware can do.
> It gets installed by exploiting more than 20,000 common misconfigurations
That's probably a very long-winded and hand-wavy way to say they are probably using Metasploit or similar.