Linux users warned of new Trojan danger

Remote Shell worm could cause more damage than Code Red

James Middleton

Security companies are warning Linux users over a new and dangerous Trojan that may have originated in the UK.

The Trojan contains self-replicating virus-like capabilities and has similarities to the Windows-based Back Orifice tool, putting Linux boxes at risk of remote control.

Advertisement

The so-called Remote Shell Trojan spreads through email as well as replicating itself across the infected system. It installs a backdoor which listens for incoming connections on UDP port 5503 or higher, and allows remote attackers to connect to, and take control of, an infected system.

The Trojan is most dangerous if it is executed by a privileged user as it inherits the credentials of that user, effectively allowing it to take full control.

Qualys, the security firm claiming to have discovered the worm, said: "Once a system is infected, the Remote Shell Trojan calls home to a UK-based website."

The company explained that this would allow hackers to accumulate lists of infected servers which could be used "to construct chronic distributed denial of service attacks on specified targets".

Qualys also warned that the size and scope of the Trojan could be massive. Over 58 per cent of websites worldwide currently use Apache servers for which Linux is the most popular platform.

If the worm turns into an epidemic this gives it more potential for damage than Code Red, which affected Windows NT servers that account for just 25 per cent of website servers, according to Qualys.

More information and a worm removal tool can be found here.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

nasty_virus

Rare Linux virus on the loose

'RST.b' similar to Remote Shell Trojan found in October

FBI checks out Code Red suspects

Warnings of second Code Red variant

Code Red plague on the rampage

Code Red is spreading like wildfire and is attacking more than just the server.

Virus hits Windows and Linux

Source code for 'harmless' virus poses real threat.

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

IT white papers

Search white papers

Top categories

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file...

Dell Adamo XPS

Dell launches ultra-thin Adamo XPS

World's thinnest laptop will be available by Christmas

Top 10 articles, 6 November 2009

The worst Microsoft products of all time, and a USB...

Iain Thomson

Pirate Bay shutdown could be inspiring online militancy

Recent Swedish attacks raise worrying possibility

Primary Navigation