HomeSecurityAttacks targeting Linux servers install SpeakUp Trojan

Attacks targeting Linux servers install SpeakUp Trojan

TrojanSecurity researchers recently discovered an attack campaign targeting Linux servers to install a new backdoor Trojan called SpeakUp.

According to Check Point Research, the attacks are currently targeting servers in East Asia and Latin America. The attack begins by exploiting CVE-2018-20062, a reported vulnerability affecting ThinkPHP. It then uses command-line techniques to upload a PHP shell, which is responsible for delivering and executing the SpeakUp Trojan as a Perl backdoor.

During execution, the SpeakUp Trojan constantly communicates with the C&C server to receive various instructions. It can use the newtask command to execute arbitrary code or execute a file from a remote server, for example. This allows SpeakUp to provide additional backdoors, each of which is equipped with a Python script designed to scan and infect more Linux servers on internal and external subnets.

Additionally, the Trojan can exploit the newconfig command to update the configuration file for XMRig, a cryptocurrency miner used to monitor infected servers.

Linux Servers Under Attack

SpeakUp is not the only malware targeting Linux servers. Instead, these servers are attacked by a range of malware.

In December 2018, security firm ESET identified 21 malware families that serve as OpenSSH backdoors. Around the same time, Anomali Labs revealed the discovery of Rabbit and Rabbot Linux, two malware families that targeted Linux servers in Russia, South Korea, the UK, and the US and were capable of installing crypto miners.

Also in December, Bleeping Computer learned of a new attack campaign that used IPMI (Intelligent Platform Management Interface) cards to infect Linux servers with JungleSec ransomware.

How to protect yourself from SpeakUp Trojan

Security professionals can help protect against the SpeakUp Trojan by using a unified endpoint management (UEM) tool to monitor assets like Linux servers for any malicious activity. Experts also recommend timely application of patches to defend endpoints against miners and investing in education and training to help cultivate a security-conscious workforce.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS