
Hacking campaigns have been targeting vulnerabilities in Linux servers for almost a decade, without being noticed.
According to BlackBerry, the company, which is linked to the Chinese government, is conducting hacking and cyber espionage against various industries, for the purposes of stealing and collecting intellectual property data.
A recently discovered part of the campaign has been exploiting vulnerabilities since at least 2012, without being noticed all this time.
Eric Cornelius, chief product architect at Blackberry, said that this is a recently discovered campaign, but it is not new at all.
Because Linux is not typically a technology that users, security companies tend to focus less on it. So malicious actors have found an opportunity to exploit its unspecified vulnerabilities and go unnoticed all these years.
Attackers are scanning Red Hat Enterprise, CentOS, and Ubuntu Linux environments across a wide range of industries, trying to identify servers that are out of date.
This way, attackers gain access to sensitive information and data, but by infecting the servers themselves, they can also create a backdoor in the network, which provides them with a way to return to it whenever they wish.
By hacking servers, it is much easier to exfiltrate data, as data transfers to a c&c server can be disguised as internet.
Attackers are careful to do as little damage to networks as possible to avoid detection – and therefore continue campaigns for as long as possible.
However, during these campaigns, the attackers left some traces behind, which allowed researchers to attribute the campaign to hackers from China, who were even associated with the Chinese government.
