Researchers have discovered a new malware , dubbed EvilGnome, targeting Linux systems and appearing as a Gnome extension. It is a spyware, which researchers have linked to the Gamaredon Group.
Researchers were surprised when they discovered the spyware in early July, because the Linux desktop is not a popular choice among users.
Experts said that this spyware has not appeared before.

The Gamaredon group was first identified in 2013. Last year, researchers described an espionage campaign, known as Operation Armageddon, targeting Ukrainian entities. The Security Service of Ukraine (SBU) had blamed Russia.
Researchers discovered that the malicious code was created on July 4th.
EvilGnome allows for taking screenshots, stealing files, stealing audio recordings, and downloading and executing payloads.
Typically, hackers launch the attack by sending spear-phishing emails to their victims, which contain infected attachments. The malware is distributed via Russian hosting providers.
The provider used by the attackers for EvilGnome is the same as the one used by the Gamaredon group.
Spyware consists of several parts, which do different things:
ShooterSound: – records sound from the user's microphone.
ShooterImage: – takes screenshots
ShooterFile: – scans files
The malware is quite powerful, as it supports many commands and has the ability to download and execute files, set new filters for scanning, stop various operations, and much more.
“EvilGnome is a rare type of malware that targets Linux desktop users. We have found sufficient evidenceto link EvilGnome to the Gamaredon group,” the research team said. “We believe this is an early test version. We anticipate that other newer versions will be discovered and examined in the future, which could potentially provide more insight into the Gamaredon group’s activity.”
