Fancy Bear is moving into Linux malware null


The NSA and FBI have released a new cybersecurity advisory warning that Russian government hackers known as Fancy Bear have begun deploying a previously undisclosed malware which targets Linux systems.
The hackers in question, also known as APT28 or Stronium, work for Russia’s General Staff Main Intelligence Directorate’s 85th Main Special Service Center (military unit 26165) and refer to their new malware strain as Drovorub. The malware is a rootkit designed to infect and take control of Linux systems in order to steal their files and Fancy Bear is using it against targets valuable to the Kremlin.
The NSA and FBI provided more details on Drovorub’s capabilities in their cybersecurity advisory, saying:
“Drovorub is a Linux malware toolset consisting of an implant coupled with a kernel module rootkit, a file transfer and port forwarding tool, and a Command and Control (C2) server. When deployed on a victim machine, the Drovorub implant (client) provides the capability for direct communications with actorcontrolled C2 infrastructure; file download and upload capabilities; execution of arbitrary commands as “root”; and port forwarding of network traffic to other hosts on the network.”
Drovorub malware
Drovorub’s kernel module is one of the most dangerous parts of this new malware strain as it is able to hook into a Linux system’s kernel to intercept and filter system calls. This prevents users, admins and even automated antivirus software from observing the malware’s activities as well as its files.
The NSA and FBI also pointed out in their advisory that detecting the malware’s activity on a large scale is quite difficult because the malware “hides Drovorub artifacts from tools commonly used for live-response at scale”.
Being as Fancy Bear is a unit of the Russian military, the group often works on extremely high-value areas that the Kremlin has an interest in and it frequently targets entities in the defense, government, and aerospace industries. It is believed that the group is responsible for hacking the Democratic National Committee in 2016 as well as targeting the World Anti Doping Agency in 2019.
In order to better detect Drovorub’s presence on their systems, the NSA and FBI recommend that organizations block untrusted kernel modules, keep their Linux installations up to date and use kernel version 3.7 or later. Unfortunately though, these measures will not prevent the malware from an infecting a Linux system but will only make it easier to detect.
Via The Register
The NSA and FBI have released a new cybersecurity advisory warning that Russian government hackers known as Fancy Bear have begun deploying a previously undisclosed malware which targets Linux systems. The hackers in question, also known as APT28 or Stronium, work for Russia’s General Staff Main Intelligence Directorate’s 85th Main…
Recent Posts
- With the Humane AI Pin now dead, what does the Rabbit R1 need to do to survive?
- One of the best AI video generators is now on the iPhone – here’s what you need to know about Pika’s new app
- Apple’s C1 chip could be a big deal for iPhones – here’s why
- Rabbit shows off the AI agent it should have launched with
- Instagram wants you to do more with DMs than just slide into someone else’s
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010