Antivirus provider Kaspersky uncovers a sophisticated piece of 'StripedFly' malware camouflaged
as a cryptocurrency miner that's been targeting PCs for more than five years.
Antivirus provider Kaspersky uncovers a sophisticated piece of 'StripedFly' malware camouflaged as a cryptocurrency miner that's been targeting PCs for more than five years.
On Linux, the malware assumes the name 'sd-pam'. It achieves persistence using systemd services, an autostarting .desktop file, or by modifying various profile and startup files, such as /etc/rc*, profile, bashrc, or inittab files.
And it doesn't say how this is achieved without already having root privilegies. I'm not sure I believe this can in fact infect a Linux system, except if it's already heavily compromised, for instance by a user logging in as root as default.
I wasn't intentionally trying to imply that it came from the article. That's why I posted the naked link. I wasn't really thinking about the Linux component when I posted the article.
It does though:
"On Linux, the malware assumes the name 'sd-pam'. It achieves persistence using systemd services, an autostarting .desktop file, or by modifying various profile and startup files, such as /etc/rc*, profile, bashrc, or inittab files."
According to Kaspersky, StripedFly uses its own custom EternalBlue attack to infiltrate unpatched Windows systems and quietly spread across a victim’s network, including to Linux machines.
Yeah I call bullshit on that. Absolutely zero description of any vulnerability.
From what it's describing, it sounds like it would only impact Linux computers that allow SMB1 access, such as domain-joined systems with samba access allowed. It sounds like this would target mainly enterprise Linux deployments but home Linux setups should be fine for the most part.
You should always have a file your home folder named SSH keys and Root password. /s
That's not just poor configuration, that's complete disregard for security.
I won’t argue about the legitimacy of crypto simply because I don’t care enough but you have to be fucking stupid to run non-FOSS crypto miners and instead go with something proprietary like this and then be surprised it fucks up your shit.