Threats to Linux computers are now appearing on a regular basis and what was once considered “no-virus zone” has begun to be targeted by malware authors.
The most recent of these threats is a Trojan with Backdoor capabilities called Linux.BackDoor.Xupes and it was discovered by Dr.Web security researchers over the weekend.
According to the Russian antivirus company, this trojan consists of two parts. So, there is a dropper component written in Free Pascal that aims to infect computers and then, downloads the second part, which is the actual malware payload, the main body of the Backdoor trojan, coded in C.
In the case of Linux.BackDoor.Xunpes, the dropper is hidden inside a Bitcoin payment app (in this case, Bitcoin ATM by Pay Maq), which explains how the malware infects Linux computers. While the dropper itself is quite generic and is used by other malware, the backdoor, despite being quite small, includes support for several commands.
Once a computer is infected, the malware author can send over 40 different types of commands to each infected host. All commands are sent through a C&C (command and control) server, which allows the backdoor owner to remain semi-anonymous.
After analyzing the Trojan, Dr.Web security researchers stated that Linux.BackDoor.Xunpes can execute some of the following commands:
→ Download other files
→ Execute files
→ Copy files
→ Rename files
→ Delete files
→ Create folders
→ Delete folders
→ Execute bash commands
→ Simulate keystrokes
→ Log keystrokes
→ Upload keylogger files to a server
→ Capture desktop screenshot
→ Upload images to a server
→ Continuous scan for open socket status
→ End communications
→ Self-disable
Last week, a similar trojan with screenshotting capabilities was discovered again . This trojan was named Linux.Ekocms and caused quite a stir, being one of the first pieces of Linux malware with full screengrab capabilities ever detected.
If that wasn't scary enough, there's also the Linux.Encoder ransomware that has been terrorizing server admins for the past few months. Fortunately, Bitdefender researchers have managed to crack the ransomware time and time again.
And let's not forget the malicious software DDoS XOR and the Trojan Linux.Rekoobe, which also target only Linux machines.
While Linux users believed their operating system was special or somehow impervious to malicious software, they are gradually waking up and facing the harsh truth. It was never “magical” exempt from anything concerning security, and as their operating system becomes increasingly popular, malware authors will focus more of their efforts on this valuable OS.

