Security researchers have discovered a new remote access trojan (RAT) for Linux systems that maintains a nearly invisible profile by hiding tasks scheduled to run on a non-existent day, February 31st.

See also: Hackers deploy Linux malware on e-commerce servers
Dubbed CronRAT, the malware is currently targeting web stores and allows attackers to steal credit card data by deploying online payment skimmers on Linux servers.
CronRAT, which is highly inventive and complex, is not detected by many antivirus engines.
It abuses the Linux task scheduling system, cron, thereby allowing scheduled tasks to be executed on non-existent calendar days, such as February 31st.
The Linux cron system accepts date specifications as long as they are in a valid format, even if the day does not exist in the calendar. This means that the scheduled job will not be executed.
This is what CronRAT relies on to achieve its goal. According to a report by Dutch cybersecurity firm Sansec, the Linux trojan hides a “complex Bash program” in the names of scheduled tasks.
"CronRAT adds a number of tasks to the crontab with a strange date specification: 52 23 31 2 3. These lines are syntactically valid, but will generate a runtime error when executed. However, this will never happen as they are scheduled to run on February 31," the Sansec researchers explain.
See also: Android malware BrazKing returns as a banking trojan
The code includes commands for self-destruction, timing configuration, and a custom protocol that allows communication with a remote server.
The researchers note that the trojan contacts a command and control (C2) server (47.115.46.167) using a "Linux kernel feature that allows TCP communication through a file."

Additionally, the connection is made via TCP over port 443, using a fake banner for the Dropbear SSH service, which also helps the malware remain hidden.
After contacting the C2 server, the disguise is revealed, sends and receives several commands, and receives a malicious library. At the end of these exchanges, the attackers behind CronRAT can execute any command on the compromised system.
See also: SharkBot: The new Android banking trojan targeting banks in Europe
Sansec describes the new malware as "a serious threat to Linux e-commerce servers," due to its capabilities:
- Run without file
- Timing configuration
- Anti-tampering checksums
- Controlled via binary, fuzzy protocol
- Launches the tandem RAT in a separate Linux subsystem
- Control server disguised as a “Dropbear SSH” service.
- The payload is hidden in legitimate CRON job names
All of these features make CronRAT virtually undetectable. Sansec notes that CronRAT's new execution technique also bypassed the eComscan detection algorithm, and researchers had to rewrite it to detect the new threat.
