HomeSecurityMagnet Goblin distributes Linux malware via 1-day flaws

Magnet Goblin distributes Linux malware via 1-day flaws

A financially motivated hacking group called Magnet Goblin is using various 1-day vulnerabilities to compromise servers affecting public users and deploy custom malware on Windows and Linux systems.

See also: GTPDOOR Linux malware exploits GPRS networks

Magnet Goblin Linux malware

1-day bugs refer to vulnerabilities that have been publicly disclosed and for which a patch has been released. Malicious actors who want to exploit these flaws must do so quickly before a target can apply security updates.

analysts who discovered Magnet Goblin report that these hackers are quickly exploiting newly disclosed vulnerabilities, in some cases exploiting flaws 1-day after a PoC, to distribute Linux Malware.

Some of the devices or services targeted by hackers include Ivanti Connect Secure (CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, CVE-2024-21893., Apache ActiveMQ, ConnectWise ScreenConnect (, -2023-41265, CVE-2023-41266, CVE-2023-48365) and Magento (CVE-2022-24086).

Magnet Goblin exploits the flaws to infect servers with custom malware, particularly NerbianRAT and MiniNerbian, as well as a custom variant of the WARPWIRE JavaScript stealer.

NerbianRAT for Windows has been known since 2022, but Check Point now reports that an improperly compiled but effective variant of the malware for Linux, used by Magnet Goblin, has been circulating since May 2022.

Upon first launch, the malware performs preliminary actions, including collecting system information such as time, username, and machine name, generating a bot, setting a hardcoded IP address as the primary and secondary host ,setting the working directory, and loading an RSA public key for encrypting (AES) network communication.

After that, NerbianRAT loads its configuration, which specifies activity times (work time), time intervals for communication with the command and control (C2) server, and other parameters.

See also: Company announcement about the Free Download Manager site that spread Linux malware

Magnet Goblin distributes Linux malware via 1-day flaws

The C2 can send one of the following actions to the malware to execute on the infected system:

  • Perform more actions
  • Running a Linux command in a new thread
  • Sending command result and cleaning the file
  • Execute a Linux command directly
  • Complete hibernation
  • Modify connection interval
  • Adjust and save work time settings
  • Return results of idle, configuration, or command timings
  • Update a specific configuration variable
  • Refresh buffer for C2 execution commands

MiniNerbian is a simplified version of NerbianRAT, which is mainly used for executing commands and supports the following actions:

  • Execute C2 command and return results
  • Update activity schedule (all day or specific hours)
  • Configuration update

MiniNerbian communicates with the C2 via HTTP, differentiating it from the more complex NerbianRAT, which uses raw TCP sockets for communication.

Check Point says that identifying specific threats like attacks among the vast volume of 1-day exploit data, as in the case of Linux malware, is difficult, allowing these groups to hide in plain sight in the chaos that follows flaw disclosure.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: ANY.RUN Sandbox: Allows SOC and DFIR teams to analyze advanced Linux malware

Magnet Goblin distributes Linux malware via 1-day flaws

How can we protect ourselves from '1-day flaws'?

To protect yourself from 1-day flaws, such as those exploited by Magnet Goblin to distribute Linux malware, we must first understand the importance of keeping our software up to date. Updates often include fixes for known vulnerabilities, thus preventing their exploitation. In addition, using security tools, such as antivirus and intrusion prevention systems, can help detect and prevent attacks that exploit these vulnerabilities. Finally, implementing security best practices, such as using strong passwords, securing network connections, and limiting the use of administrator, can reduce the likelihood of a successful attack.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS