Kaspersky has detected a Linux version of the DinodasRAT backdoor, which targets users in China, Taiwan, Turkey, and Uzbekistan.

DinodasRAT, also known as XDealer, is designed to collect various sensitive data from compromised computers.
In October 2023, cybersecurity firm ESET revealed that a government entity in Guyana had been targeted as part of a cyberespionage campaign dubbed Operation Jacana . The Windows version of DinodasRAT was used in that attack
See also: Iranian hackers Charming Kitten use new BASICSTAR backdoor
Last week, Trend Micro reported malicious activity from a group known as Earth Krahang, which has also turned to using DinodasRAT and is targeting multiple government entities worldwide.
The use of DinodasRAT has been attributed to various Chinese groups, including LuoYu, which shows that hackers acting on behalf of the country often use the same tools.
Now, Kaspersky says it discovered a Linux version of the malware (V10) in early October 2023. Evidence gathered so far shows that the first known variant (V7) dates back to 2021.
It primarily targets Red Hat and Ubuntu Linux- based distributions . When executed, it establishes persistence on the host using SystemV or SystemD startup scripts and communicates with a remote server over TCP or UDP to retrieve commands to execute.
See also: RustDoor MacOS Backdoor: Targets Cryptocurrency Companies with Fake Job Opportunities
DinodasRAT can perform operations file, change command and control (C2) addresses, terminate processes, execute shell commands, download a new version of the backdoor, and uninstall itself, if necessary.
Additionally, it can evade detection and uses Tiny Encryption Algorithm (TEA) to encrypt C2 communications.
“"The main use case for DinodasRAT is to gain and maintain access via Linux servers," Kaspersky said. "The backdoor is fully functional, giving the operator complete control over the infected machine, allowing data extraction and espionage.“.

Protection
Organizations can protect their networks from the DinodasRAT backdoor by implementing various security. First, it is important to keep their systems up to date. This means they should regularly install the latest updates and security patches on all operating systems and applications.
See also: Russian Turla hackers target NGOs with new TinyTurla-NG backdoor
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Additionally, organizations should use security solutions that include intrusion detection and malware protection. These solutions can help detect and prevent attacks.
Staff training is also critical to avoiding the DinodasRAT backdoor. Employees need to be aware of the risks associated with cybersecurity and the tactics used by attackers, such as phishing.
Finally, organizations should implement the principle of least privilege. This means that users and devices should only have the necessary access permissions they need to perform their tasks.
Source: thehackernews.com
