HomeSecurityWellMess malware targets both Linux and Windows devices

WellMess malware targets both Linux and Windows devices

WindowsIt's now widely accepted that Linux and Mac are more secure operating system choices than Microsoft Windows. But that doesn't mean hackers aren't finding ways to infect machines running those operating systems as well – we've previously heard about the massive Mirai botnet, which controlled networking devices running Linux.

The creators of Mirai used the Golang programming language (also known as Go) to write the malware code. Just recently, security researchers at JPCERT (Via: TechRepublic) found another malware written in Go. It is cross-platform and comes in two versions.

Dubbed WellMess, this malware affects both Linux and Windows operating systems. While the core functionality of both versions of the malware remains the same, there are some minor differences.

Like other malware, WellMess communicates with its command & control (C&C) center for further actions. Commands could be given from the C&C server to upload/download files and execute arbitrary shell commands. The Windows version also has the ability to execute PowerShell actions.

The commands are sent to the infected devices in the form of an encrypted HTTP Post request. The cookie header data is encrypted with RC6. But that's not all. WellMess also has a version developed on the .Net Framework. The cookie data in the .Net version is the same as the Go version.

According to JPCERT, the attacks were detected in Japanese organizations and may continue in the future.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS