This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.  > Find out more here

 

All the latest UK technology news, reviews and analysis

Researchers dissect Linux server rootkit

by Shaun Nichols

21 Nov 2012

View Comments

  • Tweet this
bug malware virus security threat breach

A recently discovered rootkit could provide researchers with insight on the direction being taken in the malware space, security experts have claimed.

Security researchers have begun issuing reports on an unnamed and previously unknown Linux rootkit posted earlier this month to a security mailing list.

While early analysis has found that the attack is relatively crude by Windows rootkit standards, the attack has caught the eye of vendors at it appears to be a commercially-designed sample rather than a targeted attack.

Researchers believe that the rootkit is intended for use on web servers, infecting 64-bit Linux kernels and then injecting further attack code into web pages.

The discovery of the rootkit could indicate that cybercriminals are increasingly looking to infect Linux systems with sophisticated attacks. Rootkits, which run at the kernel level of a system, have emerged as a favourite means for avoiding the detection of conventional antivirus software.

"Although the code quality would be unsatisfying for a serious targeted attack, it is interesting to see the cyber-crime-oriented developers, who have partially shown great skill at developing Windows rootkits, move into the Linux rootkit direction," security firm CrowdStrike wrote in its analysis of the malware.

"The lack of any obfuscation and proper HTTP response parsing, which ultimately also led to discovery of this rootkit, is a further indicator that this is not part of a sophisticated, targeted attack."

CrowdStrike researchers also suggested the attack is likely the work of a specially-contracted developer and has since been modified by the buyer.

Marta Janus, a researcher with Kaspersky Labs, suggested that the attack could also signal a shift away from high-level attacks on HTTP servers to more sophisticated methods with infect the server itself and poison hosted web pages.

"This rootkit, though it's still in the development stage, shows a new approach to the drive-by download schema and we can certainly expect more such malware in the future," Janus wrote.

Do you agree

blog comments powered by Disqus

Poll

Business security poll

How concerned are you by the rising tide of cyber threats?

17%

54%

11%

9%

9%

Popular Threads

Powered by Disqus
Samsung Galaxy S4 V3

Samsung Galaxy S4 video review

A solid Android smartphone let down by less than stellar software

Updating your subscription status Loading

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

newsletter sign-up button

mcafee

7 requirements for hybrid web delivery

It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model

navisite

BYOD: the implications for the IT team

BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs

SAS IMM Lead/SAS MA/SAS MO/SAS MOM/SAS RTDM/Perm/London

SAS IMM Lead/SAS MA/SAS MO/SAS MOM/SAS RTDM/BI/Perm/London...

Capacity Manager

Key accountabilities This role will be leading the...

SAP Logistics Senior Associate

SAP Logistics Senior Associate - Manchester office base...

Sharepoint Consultant

Proteus Europe is currently recruiting for a large European...

To send to more than one email address, simply separate each address with a comma.