The APT27 hacking group, better known as “Iron Tiger,” has created a new Linux version of its SysUpdate remote access malware. With this modification, the Chinese cyberespionage group can target a wider range of enterprise services.
According to a new report from Trend Micro, hackers first tested the Linux version in July 2022. However, it wasn't until October that they began spreading their payloads.
The new malware variant is written in C++ using the Asio library and its functionality is very similar to the Iron Tiger team's SysUpdate version for Windows.
Last summer, SEKOIA and Trend Micro reported that the APT27 threat actor had seen an increased interest in targeting systems beyond Windows. This attack used a new backdoor called “rshell.” It’s clear that they’ve shifted their focus to include Linux and macOS devices as well.

APT27's latest campaign
Trend Micro conducted an examination of the SysUpdate campaign and its findings revealed that Windows and Linux samples were deployed against legitimate targets.
One of the victims of this campaign was a gaming company in the Philippines, whose attack used a command and control server registered with a domain similar to the victim's brand.
Although the exact origin of this infection is unknown, Trend Micro analysts believe that chat apps were used to trick employees into downloading malicious files.
One element that has evolved compared to previous SysUpdate-based campaigns is the loading process, which now uses a legitimate and digitally signed “Microsoft Resource Compiler” executable (rc.exe) to perform DLL side-loading with rc.dll to load the shellcode.
See also: Dish Network confirms ransomware attack
The shellcode loads the first stage of SysUpdate into memory, making it difficult for AVs to detect. It then moves the required files to a hardcoded folder and establishes persistence with Registry modifications or by creating a service, depending on the process permissions.
The second stage will start after the next system reboot to decompress and load the main SysUpdate payload.

With its wide set of features, SysUpdate can pose a threat to anyone's security when it falls into the wrong hands.
Trend Micro discovered that the Iron Tiger group used a signed Wazuh executable in the later stages of sideloading, in an attempt to integrate into the victim's environment, given that the target organization in question was using a valid Wazuh platform.
See also: SCARLETEEL Hacker: How do they steal source code and data?

New Linux version of SysUpdate
The Linux variant of SysUpdate is an ELF executable and shares common network encryption keys and file management functions with the Windows counterpart.
The binary supports five parameters that determine what the malware should do next: setting persistence, daemonizing the process, setting a GUID (Globally Unique Identifier) for the infected system, etc.

The malware restores persistence by copying a script to the “/usr/lib/systemd/system/” directory, an action that requires root user privileges.
When it starts, it sends the following information to the C2 server:
- GUID (randomly selected if its parameter has not been used before)
- Hostname
- Username
- Local IP address and port used to send the request
- Current PID
- Kernel version and machine architecture
- Current file path
- Boolean (0 if it started with exactly one parameter, 1 otherwise)
The Linux SysUpdate variant has a notable new feature, DNS tunneling, which has only been detected in a sample of Windows malware so far.
SysUpdate retrieves DNS information from the “/etc/resolv.conf” file to retrieve the default DNS system IP address that can be used to send and receive DNS queries. If that fails, it uses Google ’s DNS server at 8.8.8.8.
Using this system, one can bypass any firewalls or security tools that are configured to only accept traffic from a whitelist of IP addresses.
See also: Aruba Networks patches six critical vulnerabilities in ArubaOS
Based on the choice of Asio Library to develop the Linux variant of SysUpdate, Trend Micro assumes that this cross-platform will likely lead to a macOS in the near future.
Information source: bleepingcomputer.com
