Mumblehard: Smart malware turns Linux machines into spambots! – Thousands of computers and web servers running Linux and FreeBSD have been “infected” over the last five years with a “smart” malwarethatturns infected machines into spambots.
As cybersecurity reports, the new malware was discovered by security researchers at ESET and named “Mumblehard” (its name comes from: Muttering spam from your servers).
ESET security researchers recorded more than 8,500 unique IP addresses during the seven-month investigation, which are associated with machines infected with the Mumblehard malware.
Main characteristics of the Mumblehard malware:
Backdoor
Spamming daemon
Both features are written in the Perl programming language. Also, the Backdoor allows malicious users to infiltrate the infected system and take full control of it, while the Spamming daemon is a hidden process that focuses on sending a large number of spam emails from the infected system.
Mumblehard malware is causing concern among security researchers
The Mumblehard malware is causing concern among security researchers because it has been active for at least the last five years without any interruption and without being detected by anyone.
How does Mumblehard malware penetrate the server operating system?
The MUMBLEHARD malware exploits vulnerabilities in popular platforms (cms) such as WordPress and Joomla in order to penetrate the server's Linux or FreeBSD operating system.
Also, the MUMBLEHARD malware is installed by "pirated" versions of a program called DirectMailer (by Yellsoft) for Linux and BSD operating systems.
How to protect yourself from Mumblehard?
Web server administrators should check servers for unwanted cronjob entries, which will have been added by the malware to activate the backdoor, a process that runs every fifteen minutes.
Additionally, the backdoor is usually installed in the folder: /var/tmp or /tmp. Finally, you can disable the backdoor by noexec the tmp folder.
Source: zougla.gr

