A new malware, dubbed FontOnLake, is infecting Linux systems and hiding in legitimate binaries. According to researchers, FontOnLake has backdoor and rootkit components.
The malware is not particularly widespread but benefits from an advanced design that allows it to maintain extended persistence on an infected system.
See also: ShellClient Malware: Used in aerospace companies

FontOnLake hides in legitimate utilities
FontOnLake has multiple modules that interact with each other and allow communication with the malware operators, while stealing sensitive data and remaining hidden in the system.
Security researchers at ESET have found several samples of this malware on the VirusTotal. The first one appeared in May 2020.
The researchers noted that FontOnLake's design is particularly careful. The malware , which targets Linux systems, is likely used in targeted attacks by criminals who are careful enough to use unique command and control (C2) servers for "almost all samples" and various non-standard ports.
See also: How a coding bug turns AirTags into malware distributors
While ESET researchers have determined that the distribution method for the FontOnLake malware is via a trojanized app, they do not know how victims are tricked into downloading the modified binaries.
Among the Linux utilities that the threat actor modified to deliver FontOnLake are: cat, kill, sftp, sshd.
“All trojanized files are standard Linux utilities and serve as a persistence method because they are usually executed at system startup,” said Vladislav Hrčka, malware analyst and reverse engineer at ESET.
Researchers believe that the trojan utilities were likely modified at the source code level.
In addition to transporting malware, the role of these modified binaries is to load other malicious payloads onto infected Linux systems, collect information, or perform other malicious actions.
Researchers discovered three custom backdoors written in C++, related to the FontOnLake malware, that provide operators with remote access to the infected system.
A common function of all three is the transfer of stolen sshd credentials and bash command history to the C2 server.

Based on open-source rootkit
In their report, ESET researchers state that the presence of FontOnLake on a compromised Linux system is hidden by a rootkit component, which is also responsible for updates and for delivering backup backdoors.
The communication between trojanized apps and the rootkit is done through a virtual file created by the latter. An operator can read or write data to this file and extract it from the backdoor component.
Researchers believe that the creator of FontOnLake is “very experienced in cybersecurity” and disabled the C2 servers used in the samples found on VirusTotal.
See also: Android malware has stolen money from 10 million users!
ESET says that FontOnLake may be the same malware previously analyzed by researchers at the Tencent Security Response Center.
Cybersecurity firm Avast said in August that it had found a new malware targeting Linux systems. Their description is similar to ESET's findings.
“The main purpose of the rootkit component is to hide the stage 2 payload and ensure that traffic from the CNC bypasses the firewall by installing a netfilter hook and redirecting CNC packets to appear to originate from localhost,” Avast said.
Source: Bleeping Computer
