Stantinko, one of the oldest malware botnets, has updated its Linux malware, upgrading its trojan to appear as the legitimate Apache web server (httpd) in order to make detection more difficult on infected hosts.
The updates, detected by security firm Intezer Labs, confirm that despite the period of inactivity – in terms of code changes – the Stantinko botnet continues to operate today.
The Stantinko botnet was first detected in 2012. The group behind this malware began operating by distributing the Stantinko Trojan as part of application bundles or through pirated applications. As the botnet grew and became more profitable, its code evolved. A significant update was discovered in 2017 when security firm ESET found that Stantinko used some special versions of its malware for Linux systems.

The last version of Stantinko's Linux malware was detected in 2017, with version number 1.2. But in a report released today and shared with ZDNet, Intezer Labs said they recently discovered a new version of Stantinko's Linux malware, with version number 2.17 — a huge leap from the previously known version.
However, despite the huge gap between the two versions, the Intezer team notes that the new version is actually leaner and contains fewer features than the older version, which is strange.
One reason behind this strange move is that Stantinko's gang could have stripped out all the bits and pieces from their code and left only the features that are essential and used on a daily basis. This includes the proxy feature, which is still present in the newer version, and is critical for brute-force attack functionality .
Another reason could also be that Stantinko's gang was trying to reduce the malware's fingerprint on antiviruses. Fewer lines of code means less malicious behavior to detect.
And Intezer notes that VirusTotal gave a very low detection rate to the newest version of Stantinko, saying it was almost undetectable.
Represents the Apache web server
Additionally, Stantinko's hackers appear to have modified the process name used by the Linux malware, choosing httpd, the name commonly used by the more popular Apache web server.
This was apparently done for server owners, wanting to avoid detecting the malware during a regular visual inspection, as the Apache web server is often included by default in many Linux distributions and this process is commonly performed on Linux systems that Stantinko generally infects.
Either way, Linux system administrators should realize that as the Linux operating system continues to spread into corporate environments, more and more malware gangs will start targeting Linux.
