HomeSecurityNew Auto-Color Linux backdoor targets universities

New Auto-Color Linux backdoor targets universities

A new Linux backdoor named "Auto-Color" was used in attacks between November and December 2024, targeting universities and government organizations in North America and Asia.

Auto-Color Linux backdoor

According to researchers at Palo Alto Networks' Unit 42, the malware evades detection and is difficult to remove from infected systems. It can maintain its access for a long time.

Auto-Color backdoor

Researchers have not identified how the initial infection occurs, but the attack begins with the execution of a seemingly legitimate file with “innocent” names such as “door”, “egg” and “log”.

See also: DarkMind Backdoor exploits LLMs capabilities

If the malware is run with root privileges, it installs a malicious library implant (libcext.so.2), disguised as the legitimate library libcext.so.0. It then copies itself to a system directory (/var/log/cross/auto-color) and modifies '/etc/ld.preload' to ensure that the implant is executed before any other system library.

If root access is not available, the Auto-Color backdoor still runs, but bypasses persistence mechanisms. This limits its long-term impact, but still provides remote access, which could allow attackers to gain root access through other means.

Auto-Color decrypts the command-and-control (C2) server information using a custom encryption algorithm and validates the exchange via a random 16-byte value handshake.

Custom encryption is used to obfuscate C2 server addresses, configuration data, and network traffic, while the encryption key changes dynamically with each request to make detection more difficult.

See also: Golang-based backdoor uses Telegram Bot API for C2 purposes

Once the connection is established, C2 instructs Auto-Color to perform one of the following actions:

  • Opening a reverse shell, allowing full remote access.
  • Execution of arbitrary commands in the system.
  • Modifying or creating files to extend infection.
  • Function as a proxy.
  • Modify its configuration.

The Auto-Color backdoor also has features rootkit-like and a built-in “kill switch,” which allows attackers to immediately delete traces of infection from compromised machines to hinder investigations.

New Auto-Color Linux backdoor targets universities

Protection

The Auto-Color backdoor poses a serious threat to Linux systems, especially those in government and academic environments.

Unit 42 researchers recommend monitoring changes to "/etc/ld.preload", which is a key persistence mechanism, and checking "/proc/net/tcp".

Additionally, organizations can protect their networks from backdoors by keeping their systems up to date. This means they should regularly install the latest updates and security patches on all operating systems and applications.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Chinese cyberspies use new SSH backdoor

Security solutions that include intrusion detection and malware protection are also required . These solutions can help detect and prevent attacks.

Finally, the principle of least access should be applied . This means that users and devices should only have the necessary access permissions they need to perform their tasks.

Unit 42 researchers have included report indicators of compromise (IoC) in their , so checking system logs and network traffic for connections to the listed C2 IPs is also crucial.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS