Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Linux version of DinodasRAT found to be involved in cyberattacks in multiple countries
    Cyber Security

    Linux version of DinodasRAT found to be involved in cyberattacks in multiple countries

    techempireBy techempire2 Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportMarch 28, 2024Editorial DepartmentLinux/Internet Security

    Linux version of DinodasRAT

    The Linux version of the multi-platform backdoor is called dinosaur rat Kaspersky’s latest findings show that the virus has been found in the wild targeting China, Taiwan, Turkey and Uzbekistan.

    DinodasRAT, also known as XDealer, is a C++-based malware capable of obtaining various sensitive data from infected hosts.

    In October 2023, Slovak cybersecurity company ESET revealed that government entities in Guyana had been targeted by a cyber espionage campaign called “Operation Water Pheasant” to deploy a Windows version of the implant.

    Internet security

    Last week, Trend Micro detailed a cluster of threat activity it’s tracking called Earth Krahang, which since 2023 has turned to using DinodasRAT to target multiple government entities around the world.

    The use of DinodasRAT has been attributed to multiple China-linked threat actors, including Luo Yu, again reflecting widespread tool-sharing among groups of hackers believed to be acting on behalf of the state.

    Linux version of DinodasRAT

    Kaspersky said it discovered the Linux version (V10) of the malware in early October 2023. Evidence collected so far suggests that the first known variant (V7) dates back to 2021.

    It mainly targets Red Hat based distributions and Ubuntu Linux. After execution, it establishes persistence on the host by using SystemV or SystemD startup scripts, and periodically contacts the remote server via TCP or UDP to obtain commands to be executed.

    Internet security

    DinodasRAT can perform file operations, change command and control (C2) addresses, enumerate and terminate running processes, execute shell commands, download new versions of the backdoor, and even uninstall itself.

    It also takes steps to evade detection through debugging and monitoring tools, and like its Windows counterpart, utilizes the Tiny Encryption Algorithm (TEA) to encrypt C2 communications.

    “The main purpose of DinodasRAT is to gain and maintain access to Linux servers, rather than for reconnaissance,” Kaspersky said. “The backdoor is fully functional and allows the operator to fully control the infected machine, allowing for data exfiltration. and espionage.”

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.