HomeSecurityFree Download Manager site redirected Linux users to malware for years

Free Download Manager site redirected Linux users to malware for years

Free Download Manager site redirected Linux users to malware for years! A reported attack on the Free Download Manager supply chain redirected Linux users to a malicious Debian package repository that was installing information-stealing malware.

The malware used in this campaign creates a reverse shell on a C2 server and installs a Bash stealer that collects user data and account credentials.

Kaspersky discovered the potential supply chain breach during its investigation of suspicious domains, finding that the campaign has been ongoing for over three years.

Although the cybersecurity company notified the software vendor about the issue, it did not receive a response, so the exact means of the breach remain unclear.

See also: WiKI-Eve: Steals passwords via WiFi

Free Download Manager site redirected Linux users to malware for years
Free Download Manager site redirected Linux users to malware for years

Kaspersky reports that the official download page hosted at “freedownloadmanager[.]org”, sometimes redirects those trying to download the Linux version to a malicious domain at “deb.fdmpkg[.]org”, which hosts a malicious Debian package.

Due to the fact that this redirection only occurs in some cases and not in all download attempts from the official website, it is assumed that the malicious codes targeted users with dangerous downloads based on specific, but unknown criteria.

Kaspersky observed various posts on social media, such as Reddit, StackOverflow, YouTube, and Unix Stack Exchange, where the malicious domain was promoted as a trusted source for obtaining the Free Download Manager tool.

Additionally, a post on the official Free Download Manager website in 2021 shows how an infected user points out the malicious domain "fdmpkg.org" and is told that it is not related to the official project.

See also: Data theft surpasses ransomware as IT professionals' biggest concern

On these websites, users had been discussing problems with the software for the past three years, exchanging opinions about suspicious files and cron jobs it created, without realizing that they were infected with malware.

While Kaspersky states that the redirection was stopped in 2022, old YouTube videos [1, 2] clearly display download links to the official Free Download Manager, redirecting some users to a malicious URL https://deb.fdmpkg[.]org instead of freedownloadmanager.org.

Free Download Manager site redirected Linux users to malware for years

The malicious Debian package, which is used to install software on Debian-based Linux distributions, including Ubuntu and its derivatives, contains a malicious information-stealing script and a crond backdoor that creates a reverse shell from the C2 server.

The crond component creates a new cron job on the system that runs a stealer script at system startup.

Kaspersky discovered that the crond backdoor is a variant of the 'Bew' malware that has been around since 2013, with the Bash stealer first detected in the wild and analyzed in 2019. However, the tool is not original.

The version of Bash Stealer analyzed by Kaspersky collects system information, browsing history, passwords stored in browsers, RMM control keys, shell history, cryptocurrency wallet data, and account credentials for AWS, Google Cloud, Oracle Cloud Infrastructure, and Azure cloud.

See also: Phishing campaign targeted 40 companies in Colombia – Hackers installed Remcos malware

The collected data is uploaded to the hackers' server, where it can be used to carry out further attacks or sold to other hackers.

If you installed the Linux version of Free Download Manager between 2020 and 2022, you should check and see if the malicious version is installed.

To achieve this, search for the following files caused by the malware and, if found, delete them.

  • /etc/cron.d/collect
  • /var/tmp/crond
  • /var/tmp/bs

Despite the “age” of the malicious tools used in these attacks, signs of suspicious activity on infected computers, and numerous reports on social media, the malicious Debian package remained undetected for years.

Kaspersky says this is due to a combined effect of factors, including the rarity of malware on Linux and limited spread due to only a portion of users being redirected to the unofficial URL.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS