HomeSecurityHackers deploy Linux malware on e-commerce servers

Hackers deploy Linux malware on e-commerce servers

Security researchers discovered that intruders develop a Linux backdoor on compromised e-commerce servers after the insertion of a credit card skimmer into the websites of online stores.

Linux e-commerce servers

The web skimmer with PHP encoding (a script designed to steal and exploit payments and customers' personal data) is added and camouflaged as a .JPG image file in the /app/design/frontend/ folder.

See also: Windows Subsystem for Linux (WSL) 0.50.2 released

Intruders use this script to download and inject fake payment forms into checkout pages displayed to customers from the compromised online store.

Linux malware that is not detected by security software

The Golang-based malware, which was detected by Dutch cybersecurity firm Sansec on the same server, was downloaded and executed on compromised servers as the linux_avp executable

Once launched, it is immediately removed from the disk and camouflaged as the “ps -ef” process that will be used to obtain a list of processes currently running.

See also: Microsoft just expanded its malware protection for Linux servers

During the analysis of the linux_avp backdoor, Sansec found that it awaits commands from a “Beijing server” hosted on Alibaba's network.

They also discovered that the malware would gain persistence by adding a new crontab entry that would re-download the malicious payload from the command-and-control server and reinstall the backdoor if it was detected and removed or the server was restarted.

Linux

So far, this backdoor remains undetected by malware protection engines on VirusTotal, even though a sample was first uploaded more than a month ago, on October 8.

See also: Google: It just tripled its bounty for Linux kernel bugs

The uploader may be the creator of linux_avp, as it was submitted one day after researchers from the Dutch cyber security company Sansec detected it during the investigation of the e-commerce site breach.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS