HomeSecurityCloud Snooper attacks cloud servers

Cloud Snooper attacks cloud servers

You may have heard the phrase associated with the Linuxthat it is the best OS when it comes to security. In general, this is true, but there are some issues with the program that can affect security .

Recently , SophosLab published a report about a new malware, called Cloud Snooper, which can compromise the security of servers based on Linux or any other operating system, through a kernel driver

Attackers can now execute commands over the networkusing the new Cloud Snooper malware.

What is Cloud Snooper?

Cloud Snooper is a new sophisticated malware thatestablishes communication with the cloud computing server, bypassing the firewall.

Cloud Snooper attacks cloud servers

How does it infect servers?

As you may know, everything in the Linux operating system is a file. So malicious actors exploit the Linux kernel driver file called “snd_floppy”.

The file name was chosen to resemble other Linux driver programs that start with “snd” such as snd_pcm, snd_hda_intel, snd_hda_codec and snd_timer.

To spy on the server, the attacker uses a signaling method, in which the hidden monitoring command is added to the regular network traffic data, to perform malicious actions.

The script operates as secret data, which is extracted from network traffic by the snd_floppy driver file. The attacker uses the 16-bit TCP source port to send the command, bypassing detection by the firewall.

How to protect the server from Cloud Snooper?

The first thing you can do is modify your current firewall security rules to detect and block packets from an illegal source port.

If your firewall still doesn't block an infected file from being registered, you can add another layer of protection to prevent a script from running. You can use any tool that can monitor and remove dangerous drivers or other unwanted programs from your server.

You can also add two-factor authentication as an extra layer of security.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS