An active malware campaign is currently targeting Linux devices running software with critical vulnerabilities. Its goal is to infect systems running vulnerable versions of the popular TerraMaster operating system, Zend Framework (Laminas Project), or Liferay Portal with the FreakOut malware, helping to deploy a broad cyberattack campaign.

“Hitting “unpatched” Linux systems
The common reason that all three software solutions are targeted by the current FreakOut campaign is that they all have a large user base and are still vulnerable to some vulnerability.
Zend Framework is a collection of professional PHP packages spanning over 570 million installations. Version 3.0.0, however, has a critical flaw (CVE-2021-3007) that could be exploited to achieve remote code execution.
Liferay Portal is a platform for Java developers to build services, user interfaces, customize applications, or deploy out-of-the-box. All open source Community versions prior to 7.2.1 have a critical vulnerability (CVE-2020-7961) that allows remote execution of arbitrary code.
TerraMaster is the operating system that powers NAS devices . Version 4.2.06 and earlier suffer from a remote command execution flaw (CVE-2020-28188, also critical) that allows hackers to take complete control of the device .
Security researchers at Check Point discovered the FreakOut attacks and say that the infected Linux devices are infected with a botnet that could help develop other cyberattacks. They say the controller could use the infected machines to mine cryptocurrency, spread laterally across a corporate network, or target other targets while impersonating the compromised company.

The FreakOut malware is new to the market and can be used for port scanning, information gathering, network sniffing, or launching DDoS attacks.
The infection begins by exploiting one of three critical vulnerabilities and continues by uploading a Python script (out.py) to the compromised computer. The attacker attempts to execute the script using Python 2, which reached end-of-life in 2020.
Check Point discovered the attack on January 8, 2021, when they observed the malicious script being downloaded from hxxp://gxbrowser[.]net. Since then, researchers have detected hundreds of attempts to download the code.
Information source: bleepingcomputer.com
