{"id":507970,"date":"2023-09-14T14:00:45","date_gmt":"2023-09-14T12:00:45","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=507970"},"modified":"2023-09-14T14:04:59","modified_gmt":"2023-09-14T12:04:59","slug":"website-served-password-stealing-linux-malware-for-3-years","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/507970-website-served-password-stealing-linux-malware-for-3-years.html","title":{"rendered":"Website served password-stealing Linux malware for 3 years"},"content":{"rendered":"<p>Security researchers at Kaspersky have <a href=\"https:\/\/securelist.com\/backdoored-free-download-manager-linux-malware\/110465\/\" target=\"_blank\" rel=\"noopener\"><strong>discovered a seemingly benign website<\/strong><\/a> has been serving Linux users with malware for over three years.<\/p>\n<p>The official Free Download Manager website (freedownloadmanager[.]org) initially only offered a non-harmful version of the Linux Free Download Manager on a Debian repository for several years.<\/p>\n<p>However, from early 2020, the domain sometimes redirected users to the <em>deb.fdmpkg[.]org<\/em> subdomain, containing malicious versions of the app.<\/p>\n<p>These versions contained an unfiltered post-install script.<\/p>\n<p>&#8220;This script drops two ELF files to the paths <em>\/var\/tmp\/crond<\/em> and <em>\/var\/tmp\/bs<\/em>,&#8221; the researchers explained. ELF files are executable files or programs Linux systems can run.<\/p>\n<p>&#8220;It then establishes persistence by creating a cron task (stored in the file \/etc\/cron.d\/collect) that launches the <em>\/var\/tmp\/crond<\/em> file every 10 minutes.&#8221;<\/p>\n<p>The executable in <em>\/var\/tmp\/crond<\/em> is then launched every time the infected Linux machine starts up and acts as a backdoor.<\/p>\n<p>The attackers use the backdoor to deploy a Bash stealer, which can collect system information such as a user&#8217;s browsing history, saved passwords, cryptocurrency wallet files, and credentials for cloud services (AWS, Google Cloud, Oracle Cloud Infrastructure, Azure).<\/p>\n<p>Kaspersky&#8217;s researchers established the version of Free Download Manager installed by the infected package was released in January 2020.<\/p>\n<p>The <em>postinst<\/em> script contains comments in Russian and Ukrainian, including information about improvements made to the malware, as well as activist statements.<\/p>\n<p>Kaspersky also found several tutorials on downloading Free Download Manager on YouTube, which showed the creators downloading the infected versions of the software.<\/p>\n<p>However, not all users were redirected to download the malicious file instead of the uninfected version.<\/p>\n<p>&#8220;It is possible that the malware developers scripted the malicious redirection to appear with some degree of probability or based on digital fingerprint of the potential victim,&#8221; the researchers said.<\/p>\n<p>They advised that users who have downloaded the malicious file remove the <em>\/etc\/cron.d\/collect<\/em>, <em>\/var\/tmp\/crond<\/em> and <em>\/var\/tmp\/bs\u00a0<\/em>to avoid future attacks, despite the campaign currently being inactive.<\/p>\n<p>The developers behind the official Free Download Manager website have not acknowledged that their website had been compromised, despite Kaspersky contacting them about the issue.<\/p>\n<p>Kaspersky also provided lists of file hashes, domains, and IP addresses to help potentially affected users determine whether their machines had been compromised and if further action was necessary.<\/p>\n<p><strong>File checksums<\/strong><\/p>\n<ul>\n<li>b77f63f14d0b2bde3f4f62f4323aad87194da11d71c117a487e18ff3f2cd468d <em>(Malicious Debian Package)<\/em><\/li>\n<li>2214c7a0256f07ce7b7aab8f61ef9cbaff10a456c8b9f2a97d8f713abd660349\u00a0<em>(crond backdoor)<\/em><\/li>\n<li>93358bfb6ee0caced889e94cd82f6f417965087203ca9a5fce8dc7f6e1b8a3ea\u00a0<em>(bs backdoor)<\/em><\/li>\n<li>d73be6e13732d365412d71791e5eb1096c7bb13d6f7fd533d8c04392ca0b69b5<em>\u00a0(atd uploader)<\/em><\/li>\n<\/ul>\n<p><strong>File paths<\/strong><\/p>\n<ul>\n<li>\/etc\/cron.d\/collect<\/li>\n<li>\/var\/tmp\/crond<\/li>\n<li>\/var\/tmp\/bs<\/li>\n<li>\/var\/tmp\/atd<\/li>\n<\/ul>\n<p><strong>Network indicators (domains and IP addresses)<\/strong><\/p>\n<ul>\n<li>fdmpkg.org<\/li>\n<li>172.111.48.101<\/li>\n<\/ul>\n<hr \/>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/507962-vumacam-launches-in-tshwane.html\" rel=\"bookmark\">Vumacam launches in Tshwane<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>Security researchers at Kaspersky have discovered a seemingly benign website of a well-known download manager has been serving Linux users with malware for over three years.<\/p>\n","protected":false},"author":341042,"featured_media":508040,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[1595,1799,801],"class_list":["post-507970","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-kaspersky","tag-linux","tag-malware"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/507970"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341042"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=507970"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/507970\/revisions"}],"predecessor-version":[{"id":508038,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/507970\/revisions\/508038"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/508040"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=507970"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=507970"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=507970"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}