Linux Threat Landscape
To quickly familiarize yourself with advanced Linux threats, we recommend reviewing the following external articles, which present the actual threat landscape, attack characteristics, exploitation areas, and post-exploitation steps. Reviewing the following materials will allow you to grasp the context which will greatly facilitate further learning quickly.
Analysis reports:
-
The Silent, Fileless Threat of VShell
-
Leaked North Korean Linux Stealth Rootkit Analysis:
-
Sindoor Dropper: New Phishing Campaign:
-
Plague: A Newly Discovered PAM-Based Backdoor for Linux
-
UNC2891 Bank Heist: Physical ATM Backdoor & Linux Forensic Evasion Evasion:
-
LD_PRELOAD still alive - The Evolution of Linux Binaries in Targeted Cloud Operations:
-
Follow the Smoke | China-nexus Threat Actors Hammer At the Doors of Top Tier Targets:
-
UNC5174’s evolution in China’s ongoing cyber warfare: From SNOWLIGHT to VShell:
-
Outlaw Linux Malware:
-
Likely Chinese Threat Actor Uses Low-Detection Linux Backdoor and NHAS Reverse SSH:
-
BPFDoor’s Hidden Controller Used Against Asia, Middle East Targets:
-
IngressNightmare: 9.8 Critical Unauthenticated Remote Code Execution Vulnerabilities in Ingress NGINX:
-
Auto-Color: An Emerging and Evasive Linux Backdoor:
-
Spinning YARN - A New Linux Malware Campaign Targets Docker, Apache Hadoop, Redis and Confluence:
-
Helldown Ransomware: an overview of this emerging threat:
-
Puma - a sophisticated loadable kernel module (LKM) rootkit:
-
Bootkity - the first UEFI bootkit for Linux:
-
How BPF-Enabled Malware Works - Bracing for Emerging Threats:
-
The Elusive GoblinRAT – The Story Behind the Most Secretive and Mysterious Linux Backdoor Found in Government Infrastructures [TRANSLATE TO EN]:
-
New Zero-Detection Variant of Melofee Backdoor from Winnti Strikes RHEL 7.9:
-
perfctl: A Stealthy Malware Targeting Millions of Linux Servers:
-
IcePeony with the '996' work culture:
-
Burning Zero Days: Suspected Nation-State Adversary Targets Ivanti CSA:
-
Bulbature, beneath the waves of GobRAT:
-
New SkidMap Linux Malware Variant Targeting Vulnerable Redis Servers:
-
Sysrv - a botnet written in Golang:
-
Breaking Down Linux.Gomir: Understanding this Backdoor’s TTPs:
-
Reptile and MEDUSA in UNC3886:
-
Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency
theft and financial gain:
-
Springtail: New Linux Backdoor Added to Toolkit:
-
Frog4Shell — FritzFrog Botnet Adds One-Days to Its Arsenal:
-
Ivanti Connect Secure: Journey to the core of the DSLog backdoor:
-
COATHANGER FortiGate RAT:
-
New Linux Remote Access Trojan targets Thailand:
-
Free Download Manager backdoored – a possible supply chain attack on Linux machines:
-
!!! Tracking interesting Linux malware !!! :
-
eBPF Linux Malware:
XorDDoS
-
Symbiote:
-
Syslogk:
Facefish Linux Rootkit
Panchan
-
Tsunami Botnet Malware:
-
IceFire Ransomware Returns | Now Targeting Linux Enterprise Networks:
-
VMware ESXi servers subjected to Akira for Linux ransomware attacks:
-
Dirty Pagetable: A Novel Exploitation Technique To Rule Linux Kernel:
-
Python-based fileless malware targets cloud workloads to deliver crypto-miner:
-
Trendmicro Linux Threat Report 2021 1H: