A new Linux rootkit malware called "Syslogk" is being used in attacks to hide malicious processes, using specially crafted packets to wake up a backdoor lying dormant on the device.
The malware is currently under intense development and its authors appear to be basing their project on Adore-Ng, an old open source rootkit.
Syslogk can force-load its modules into the Linux kernel (versions 3.x are supported), hide directories and network traffic, and ultimately load a backdoor called “Rekoobe”.
See also: Symbiote malware: Infects all running processes on Linux systems

Using magic packages to load the backdoor
Linux rootkits are malware installed as kernel modules in the operating system. Once installed, they intercept legitimate Linux commands to filter out information they don't want to be seen, such as the presence of files, folders , or processes.
Similarly, when first loaded as a kernel module, Syslogk will remove its entry from the list of installed modules to avoid manual inspection. The only sign of its presence is an exposed interface in the /proc filesystem.
See also: Black Basta ransomware: Linux version targets VMware ESXi servers

Additional features in the rootkit allow it to hide directories containing the malicious files it drops on the host, hide processes, hide network traffic, inspect all TCP packets, and start or stop remote payloads.
One of the hidden payloads discovered by Avast is a Linux backdoor called Rekoobe. This backdoor will lie dormant on a compromised machine until the rootkit receives a “magic packet” from the threat actors.
As with the magic Wake on LAN packets, used to wake up devices from sleep ,Syslogk will listen for specially crafted TCP packets that include special “Reserved” field values, “Source Port” enumeration, “Destination Port” and “Source Address” matches, and a hardcoded key.
When the appropriate magic packet is detected, Syslogks will start or stop the backdoor according to the threat actors' remote instructions, drastically minimizing the chances of detection.
Rekoobe loads in user mode, where detections are not as complex or unlikely as for Syslogk in kernel mode, so being more careful with its loading is crucial to success .
See also: How to install Linux on Windows with VirtualBox?
Rekoobe is based on TinySHell, another open-source and widely available software, and its purpose is to give the attacker a remote shell on the compromised machine.

This means that Rekoobe is used to execute commands, so the implications reach extreme levels, including information disclosure, data extraction, file actions, account takeover, and more.
Should you be worried?
The Syslogk rootkit is another example of malware for Linux systems added on top of the recently discovered Symbiote and BPFDoor, both of which use the BPF system to monitor network traffic and manipulate it dynamically .
Linux systems are not widespread among regular users, but they support some of the most valuable corporate networks out there, so threat actors spend time and effort developing custom malware for the architecture.
In the case of Syslogk, the project is in its early stages of development, so it is uncertain whether it will become a widespread threat or not. However, considering its secrecy, it will likely continue to push out new and improved versions.
The most dangerous development would be for Syslogk to release a version that supports more recent Linux kernel versions, which would significantly expand the targeting range.
Information source: bleepingcomputer.com
