Security firm ESET has discovered a new form of malware targeting Linux devices. The malware can give hackers complete control of the affected device, leaving a door open for a host of other malicious actions, such as DDoS attacks.
The new malware, named Rakos, is used to attack mobile devices and servers that have an open SSH port. If it finds an open port in the SSH protocol, it uses brute force attacks to crack the password.
ESET claims that the creators of Rakos want to infect as many systems as possible to create a botnet that they could use for other malicious attacks, such as DDoS attacks or spam spreading.
Initially, attackers scan systems for vulnerabilities by analyzing predetermined IPs. It should be noted that machines that use very weak passwords are most at risk as brute force attacks take much longer on long passwords.
Once it gains access to the victim's Linux device, Rakos starts a local HTTP service available at https://127.0.0.1:61314 for two different purposes.
“The first is a cunning way for future versions of the bot to stop various processes regardless of their name, by simply requesting the address https://127.0.0.1:61314/et and the second tries to parse a URL query with parameters “ip”, “u”, “p”, by requesting the address https://127.0.0.1:61314/ex. The purpose of this /ex HTTP is not yet clear,” according to ESET.
The malware automatically scans the infected system and collects information that it then sends to a C&C server. The information includes the IP address, usernames, and passwords.
A conf file stored locally enables access to a backdoor so that the attacker can gain access at some point in the future.
It is important to emphasize that complex SSH passwords are almost impossible to crack by this malware and attackers are mainly looking for devices that use weak passwords.
If for some reason your Linux machine is infected, you should log in using SSH/Telnet and look for a process called .javaxxx. Make sure it is the one used for unwanted connections and kill the process.
Read more in the ESET publication.
