You may have heard the phrase associated with the Linuxthat it is the best OS when it comes to security. In general, this is true, but there are some issues with the program that can affect security .
Recently , SophosLab published a report about a new malware, called Cloud Snooper, which can compromise the security of servers based on Linux or any other operating system, through a kernel driver
Attackers can now execute commands over the networkusing the new Cloud Snooper malware.
What is Cloud Snooper?
Cloud Snooper is a new sophisticated malware thatestablishes communication with the cloud computing server, bypassing the firewall.
How does it infect servers?
As you may know, everything in the Linux operating system is a file. So malicious actors exploit the Linux kernel driver file called “snd_floppy”.
The file name was chosen to resemble other Linux driver programs that start with “snd” such as snd_pcm, snd_hda_intel, snd_hda_codec and snd_timer.
To spy on the server, the attacker uses a signaling method, in which the hidden monitoring command is added to the regular network traffic data, to perform malicious actions.
The script operates as secret data, which is extracted from network traffic by the snd_floppy driver file. The attacker uses the 16-bit TCP source port to send the command, bypassing detection by the firewall.
How to protect the server from Cloud Snooper?
The first thing you can do is modify your current firewall security rules to detect and block packets from an illegal source port.
If your firewall still doesn't block an infected file from being registered, you can add another layer of protection to prevent a script from running. You can use any tool that can monitor and remove dangerous drivers or other unwanted programs from your server.
You can also add two-factor authentication as an extra layer of security.

