
Threats to Linux systems are not usually reported in the same detail as the Windows. This is mainly due to the fact that many times the attacks are not even detected by enterprise security mechanisms, and also because they are not significant enough to be widely reported by security researchers.
Of course, this doesn't mean that there aren't more serious threats to a Linux system, such as specialized malware that uses sophisticated detection evasion techniques, which can exploit already available open source code. According to cybersecurity firm Intezer, one such malware has recently emerged. It's called HiddenWasp, and what makes it quite dangerous right now is the fact that it's not detected by any of the popular anti-malware systems.
How does HiddenWasp attack Linux systems?
The first step of the malware uses the initial script to deploy the malware. The hidden script uses an sftp username with a strong password and cleans the system to eliminate older versions of the malware in case the machine was already infected.
It then proceeds to download a file from the server containing all the components, including the rootkit and the trojan. The script also attempts to add the trojan to /etc/rc.local so that it will work even after a system reboot.
The rootkit involved in the malware shares many similarities with the open source Azazel rootkit. It also shares parts of strings with the ChinaZ malware, the Adore-ng rootkit, and the Mirai malware. As for the capabilities of this malware, it can run commands in the terminal, execute files, download more scripts, etc.
Security researchers still don't know who the real creator of the malware is, but they suspect that HiddenWasp acts as a secondary payload, spreading to Linux systems that are already infected and controlled by hackers.
For more details about the new HiddenWasp malware, you can visit the Intezer blog.
