HomeSecurityNew version of Stantinko malware appears as Apache web server

New version of Stantinko malware appears as Apache web server

Stantinko, one of the oldest malware botnets, has updated its Linux malware, upgrading its trojan to appear as the legitimate Apache web server (httpd) in order to make detection more difficult on infected hosts.

The updates, detected by security firm Intezer Labs, confirm that despite the period of inactivity – in terms of code changes – the Stantinko botnet continues to operate today.

The Stantinko botnet was first detected in 2012. The group behind this malware began operating by distributing the Stantinko Trojan as part of application bundles or through pirated applications. As the botnet grew and became more profitable, its code evolved. A significant update was discovered in 2017 when security firm ESET found that Stantinko used some special versions of its malware for Linux systems.

Stantinko Apache malware

The last version of Stantinko's Linux malware was detected in 2017, with version number 1.2. But in a report released today and shared with ZDNet, Intezer Labs said they recently discovered a new version of Stantinko's Linux malware, with version number 2.17 — a huge leap from the previously known version.

However, despite the huge gap between the two versions, the Intezer team notes that the new version is actually leaner and contains fewer features than the older version, which is strange.

One reason behind this strange move is that Stantinko's gang could have stripped out all the bits and pieces from their code and left only the features that are essential and used on a daily basis. This includes the proxy feature, which is still present in the newer version, and is critical for brute-force attack functionality .

Another reason could also be that Stantinko's gang was trying to reduce the malware's fingerprint on antiviruses. Fewer lines of code means less malicious behavior to detect.

And Intezer notes that VirusTotal gave a very low detection rate to the newest version of Stantinko, saying it was almost undetectable.

Represents the Apache web server

Additionally, Stantinko's hackers appear to have modified the process name used by the Linux malware, choosing httpd, the name commonly used by the more popular Apache web server.

This was apparently done for server owners, wanting to avoid detecting the malware during a regular visual inspection, as the Apache web server is often included by default in many Linux distributions and this process is commonly performed on Linux systems that Stantinko generally infects.

Either way, Linux system administrators should realize that as the Linux operating system continues to spread into corporate environments, more and more malware gangs will start targeting Linux.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS