City
Epaper

Hackers prey on devices running open-source Linux OS

By IANS | Updated: September 12, 2020 17:30 IST

New Delhi, Sep 12 As organisations opt to use open-source operating systems worldwide, cybersecurity researchers have warned that ...

Open in App

New Delhi, Sep 12 As organisations opt to use open-source operating systems worldwide, cybersecurity researchers have warned that more and more threat actors are now executing targeted attacks against Linux-based devices while developing more Linux-focused tools.

Over the past eight years, over a dozen advanced persistent threat (APT) actors have been observed to use Linux malware or some Linux-based modules, according to cybersecurity firm Kaspersky.

Many organisations choose Linux for strategically important servers and systems, not least because this operating system is thought to be safer and less prone to cyberthreats than the far more popular Windows operating system.

There is a significant trend in many countries towards using Linux as a desktop environment by big enterprise companies, as well as in governmental entities, that pushes threat actors to develop malware for this platform.

The APT actors targeting Linux include infamous threat groups as Barium, Sofacy, the Lamberts, and Equation, as well as more recent campaigns such as, LightSpy by TwoSail Junk and WellMess," Kaspersky said in a statement.

"Diversification of their arsenal with Linux tools enables threat actors to conduct operations more effectively and with wider reach".

The myth that Linux, being a less popular operating system, is unlikely to be targeted by malware, invites additional cybersecurity risks.

"The trend of enhancing APT toolsets was identified by our experts many times in the past, and Linux-focused tools are no exception. Aiming to secure their systems, IT and security departments are using Linux more often than before," said Yury Namestnikov, head of Kaspersky's Global Research and Analysis Team (GReAT) in Russia.

"Threat actors are responding to this with the creation of sophisticated tools that are able to penetrate such systems," he added.

While targeted attacks on Linux-based systems are still uncommon, there is certainly malware designed for them – including webshells, backdoors, rootkits and even custom-made exploits.

Moreover, the small number of attacks is misleading as the successful compromise of a server running Linux often leads to significant consequences.

"These include attackers not only being able to access the infected device, but also endpoints running Windows or macOS, thus providing wider access for attackers which might go unnoticed," Kaspersky said.

Lazarus, a Korean-speaking APT group, continues to diversify its toolset and develop non-Windows malware.

"We advise cybersecurity experts to take this trend into account and implement additional measures to protect their servers and workstations," Namestnikov suggested.

( With inputs from IANS )

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: 2 Meters Down And Back: Hunting For Most Persistent ImplantsYury namestnikovRussiaNew DelhiThe new delhi municipal councilDelhi south-west
Open in App

Related Stories

InternationalRussia-Ukraine War: At Least 600 North Korean Soldiers Killed While Fighting for Russia

MaharashtraOver 10,000 Pakistani Nationals Traced in Maharashtra and Delhi Post-Palgham Terror Attack

MaharashtraMaharashtra-Russia to Jointly Develop Thorium Reactors

NationalVladimir Putin Accepts PM Modi’s Invitation To Visit India Preparations Underway, Says Russian FM Sergey Lavrov

NationalNew Delhi Railway Station Sees ‘Stampede-Like’ Chaos Due to Train Delays (Watch)

Technology Realted Stories

Technology‘WAVES 2025’ brings spotlight on India’s vibrant media and entertainment sector

TechnologyApple logs highest-ever shipment volume in India at 29 pc growth in March quarter

Technology75 pc of Indian businesses localise data as AI becomes core to strategy: Report

TechnologyPunjab starts first-of-its-kind B.Tech programme

TechnologyDynamic curriculum, continuous evolution of training modules key to stay relevant: Jitendra Singh