HomeSecurityPokemon-themed Umbreon Rootkit targets Linux systems

Pokemon-themed Umbreon Rootkit targets Linux systems

Security researchers at Trend Micro have discovered a new rootkit trojan that targets only Linux-based systems running on x86 and ARM (Raspberry Pi) platforms.

The rootkit's name is Umbreon and it was named after a Pokemon creature that lurks in the shadows, a fitting name for a rootkit.

Pokemon-themed Umbreon Rootkit targets Linux systems

According to Trend Micro, Umbreon has been used in live attacks and the company is now receiving samples for analysis from exposed devices.

The good news is that Umbreon's installation is not automated and attackers must break into a system first and then manually install the rootkit on the hacked device.

This installation process has its downsides, as well, mainly because attackers can install the rootkit in a different location on the infected system each time, making automatic detection even more difficult than it already is.

Detecting Umbreon is not easy at all. Because the trojan itself injects itself into libc functions, only tools that do not use this library can detect it.

The GNU C library (libc) is a core component of many compilers today, such as Ruby, PHP, Perl, Python, and others. Therefore, tools written in these languages ​​will not be able to detect Umbreon, which will be able to detect any commands searching for its folder or location, hide itself, and then use libc to interfere with the results.

TrendMicro says that only tools that are programmed to use Linux kernel syscalls directly will be able to bypass the rootkit's watchful eye. The company says it has created such a tool, but has not released it to the public. However, it will release some removal instructions on its website.

Umbreon, which is a ring 3 (user-level) rootkit, is somewhat easier to remove compared to a ring 0 rootkit, but non-technical administrators can damage their operating system if they are not careful.

As for technical capabilities , Umbreon is a very dangerous tool, with the ability to persist between reboots, intercept all network traffic, intercept and modify terminal commands, and even open a connection to the attacker, allowing them to log into the victim's device.

The Pokemon theme continues throughout the rootkit's code, as the SSH backdoor component that allows attackers to access devices is called Espeon, the name of another Pokemon creature.

pokemon-linux

Just as Umbreon hooks into libc to intercept terminal commands, the rootkit also hooks into libpcap in order to intercept network traffic and hide its C&C communications and the attacker's SSH sessions.

Overall, this is the work of a very talented malware developer. Trend Micro says that this threat has been active since at least 2013 and that it began developing Umbreon in early 2015.

pokemon-themed-umbreon

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS