News: 1619739618

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Stealthy Linux backdoor malware spotted after three years of minding your business

(2021/04/30)


Chinese security outfit Qihoo 360 Netlab on Wednesday said it has identified Linux backdoor malware that has remained undetected for a number of years.

The firm said its bot monitoring system spotted on March 25 a suspicious ELF program that interacted with four command-and-control (C2) domains over the TCP HTTPS port 443 even though the protocol used isn't actually TLS/SSL.

[1]

"A close look at the sample revealed it to be a backdoor targeting Linux X64 systems, a family that has been around for at least three years," Netlab researchers Alex Turing and Hui Wang [2]said in an advisory.

An MD5 signature for the file systemd-daemon first showed up in VirusTotal back on May 16, 2018 without the detection of any known malware. Two other files named systemd-daemon and gvfsd-helper were spotted over the next three years.

The association with systemd, a widely used system and session manager for Linux, may have been chosen by the malware authors to make the malicious code less likely to be noticed by administrators reviewing logs and process lists.

[3]

Netlab has dubbed the malware family RotaJakiro because it uses encryption with a rotate function and has different behavior depending on whether it's running on a root or non-root account. Jakiro is a reference to a character from the game Dota 2 .

China broke into govt, defense, finance networks via zero-day in Pulse Secure VPN gateways? No way [4]READ MORE

The malware makes an effort to conceal itself by using multiple encryption algorithms. It relies on AES to protect its own resources and a combination of AES, XOR, and rotate encryption alongside ZLIB compression to obscure its server communication.

The C2 domains with which the malware communicates were registered through Web4Africa in December 2015 and rely on hosting provided by Deltahost PTR, in Kiev, Ukraine.

[5]

The malware is not an exploit; rather it's a payload that opens a backdoor on the targeted machine. It might be installed by an unsuspecting user, an intruder, or through a dropper Trojan. How RotaJakiro has been distributed remains unanswered.

According to Netlab, RotaJakiro supports 12 commands, including "Steal Sensitive Info," "Upload Device Info," "Deliver File/Plugin," and three "Run Plugin" variants. The security firm is presently unaware of what the malware's plugins do.

The security firm sees some similarities between RotaJakiro and the Torii botnet spotted by Avast, another security company, in September, 2018. They two have some similar commands and traffic patterns, as well as functional similarities.

At least the malware is [6]starting to get noticed by antivirus software. ®

Get our [7]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YIuA2qkV5IUjeIs0SXYzAwAAAUg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://blog.netlab.360.com/stealth_rotajakiro_backdoor_en/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YIuA2qkV5IUjeIs0SXYzAwAAAUg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2021/04/20/china_pulse_connect_secure_vpn/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YIuA2qkV5IUjeIs0SXYzAwAAAUg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.virustotal.com/gui/file/a18bec90b2b6185362eeb67c516c82dd34cd8f6a7423875921572e97ae1668b0/detection

[7] https://whitepapers.theregister.com/

Disguising it as Systemd is cunning

David 132

How many admins, upon seeing a process (apparently) related to systemd sending data out on a well-known port, would assume it was malware?

I suspect that in many cases, the response would instead be a shrug and a resigned muttering of "so systemd has now extended its tentacles over TLS too? *sigh* "

Re: Disguising it as Systemd is cunning

HildyJ

I suspect that many admins don't dig enough to shrug. Many just rely on their malware scanners to tell them there's a problem.

Also, given the sophistication, the dormancy, the targeting of China, and the Ukraine destination, I wonder if this was an NSA or Five Eyes operation.

Re: Disguising it as Systemd is cunning

steelpillow

A reason to move to Devuan, then

The lack of detection is the scandal here.

Myself

So what happens to files submitted to VT, then? I thought they were made available for AV researchers to study.

This had been submitted several times over the years. Did nobody find it suspicious? Or, were they told to keep it off their detection lists?

@Myself - Re: The lack of detection is the scandal here.

Anonymous Coward

Look for the Chinese security outfit being banned from North America and Europe on the grounds of cooperating with Chinese government and/or military. Where have I seen this before ? Oh yes, Kaspersky.

The difference between common-sense and paranoia is that common-sense is
thinking everyone is out to get you. That's normal -- they are. Paranoia
is thinking that they're conspiring.
-- J. Kegler