HomeSecurityRekoobe Malware: Targets vulnerable Linux servers

Rekoobe Malware: Targets Vulnerable Linux Servers

Chinese hacking group APT31 uses Rekoobe malware to target vulnerable Linux servers.

It has been active since 2015, and in 2018, updated versions of Rekoobe were used to target Linux servers, as its architecture is x86, x64, and SPARC.

The Emergency Response Center (ASEC) shared several Rekoobe variants and organized information about the Rekoobe malware used in attacks targeting domestic companies in its latest article.

See also: New StackRot Linux kernel flaw allows privilege escalation

Rekoobe Malware

Most targets are outdated Linux or are running with improper configurations, and are also involved in supply chain attacks.

Analysis of the Rekoobe variant:

  • MD5: 8921942fb40a4d417700cfe37cce1ce7
  • C&C server: resolv.ctmailer[.]net:80 (103.140.186.32)
  • Download address: hxxp://103.140.186[.]32/mails

Rekoobe, built using the open-source Tiny shell, uses the strcpy() function to change the process name when the program is running, making it difficult for users to identify it .

It does not have any command line option to obtain the C&C server address or password.

See also: JumpCloud: Reinstates admin API keys due to an “ongoing incident”

Rekoobe generates an AES-128 key using the HMAC-SHA1 algorithm and encrypts communication data with the C&C server using said key.

Initially, data of size 0x28 is received from the C&C server, then it is split into two 0x14 bytes and used as the IV when initializing the HMAC SHA1 context.

During the initialization process, a hard-coded password string “0p;/9ol.” is also used in addition to an IV, which is every 0x14 bytes received.

The generated HMAC SHA1 values ​​are AES-128 keys, which are used to encrypt and decrypt data during its transmission to and from the C&C server, respectively.

Additionally, 0x10 bytes of integrity verification data are received from the C&C, decoded with the AES-128 key defined above, and processed via an XOR.

The data that will be delivered next is used for integrity verification - it is 0x10 bytes and must have the same value.

Once the integrity verification process is complete, the same 0x10 bytes of integrity data is transmitted to the C&C server. When sending the data, it is encrypted and transmitted using the AES128 key generated with the HMAC SHA1 value generated above.

Finally, simple commands, which are contained in one byte, are executed for file uploads, file downloads, and reverse shell.

Another Rekoobe sample opens a port in the form of a bind shell and waits for a connection from the C&C server, as Tiny SHell supports both.

See also: Cisco warns of bug that allows attackers to breach traffic encryption

Rekoobe is supposed to have a separate builder; however, it often displays a random password string, “replace with your password,” which appears to be the default string.

The attacker uses different malicious code for each attack. Unlike passwords where a different string is used each time, the data used for integrity verification is characterized by the fact that “58 90 AE 86 F1 B9 1C F6 29 83 95 71 1D DE 58 0D” is used for most of the source code.

Based on its open source code, Rekoobe could be used by attackers other than the well-known Chinese group APT31, while cases of attacks against domestic systems have increased.

To prevent such security threats, always update relevant systems to the latest versions to protect them from attacks.

Rekoobe Malware: Targets Vulnerable Linux Servers

Information source: cybersecuritynews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS