Security researchers discovered that intruders develop a Linux backdoor on compromised e-commerce servers after the insertion of a credit card skimmer into the websites of online stores.

The web skimmer with PHP encoding (a script designed to steal and exploit payments and customers' personal data) is added and camouflaged as a .JPG image file in the /app/design/frontend/ folder.
See also: Windows Subsystem for Linux (WSL) 0.50.2 released
Intruders use this script to download and inject fake payment forms into checkout pages displayed to customers from the compromised online store.
Linux malware that is not detected by security software
The Golang-based malware, which was detected by Dutch cybersecurity firm Sansec on the same server, was downloaded and executed on compromised servers as the linux_avp executable
Once launched, it is immediately removed from the disk and camouflaged as the “ps -ef” process that will be used to obtain a list of processes currently running.
See also: Microsoft just expanded its malware protection for Linux servers
During the analysis of the linux_avp backdoor, Sansec found that it awaits commands from a “Beijing server” hosted on Alibaba's network.
They also discovered that the malware would gain persistence by adding a new crontab entry that would re-download the malicious payload from the command-and-control server and reinstall the backdoor if it was detected and removed or the server was restarted.

So far, this backdoor remains undetected by malware protection engines on VirusTotal, even though a sample was first uploaded more than a month ago, on October 8.
See also: Google: It just tripled its bounty for Linux kernel bugs
The uploader may be the creator of linux_avp, as it was submitted one day after researchers from the Dutch cyber security company Sansec detected it during the investigation of the e-commerce site breach.
Information source: bleepingcomputer.com
