This free download manager site actually just redirected Linux users to malware for years
An infostealing malware campaign has been underway for at least three years, going completely unnoticed, Russian cybersecurity firm Kaspersky has revealed.
The finding came after the company decided to take a closer look at the growing number of Linux-based attacks, which “can operate for years without being noticed by the cybersecurity community.”
This example in particular focuses on what appears to be a free download manager destined for use on Debian machines, which has been available in its malicious form since January 2020.
Debian download manager malware
Affected versions of the downloadable software contain an infected postinst script that is executed upon installation, which the analysts say contains comments in both Russian and Ukrainian.
Having downloaded and installed an infected version of the software for further investigation, Kaspersky’s workers reveal that a Bash stealer is deployed to collect information such as system information, browsing history, saved passwords, cryptocurrency wallet files, and credentials for cloud services – specifically, AWS, Google Cloud, Oracle Cloud Infrastructure, Azure.
Fortunately, the researchers also revealed how the malicious version of the software had been distributed. They confirmed that the official website and its content had not been compromised, and actually, the infostealing version had been posted to online communities like Reddit and StackOverflow over a period of around two years.
The genuine makers of Free Download Manager have since been notified by Kaspersky, though at the time of writing, they had not responded.
According to Kaspersky, the threat actor targeted Linux machines specifically because they are much less frequently analyzed compared with Windows and macOS devices, simply due to popularity reasons.
Still, there are some very easy steps that users can take to protect themselves online. Most importantly, users should only download from legitimate sources and check things like domains and email addresses against what has been verified as legitimate. Doing so would have saved victims from this case of malware.
More from TechRadar Pro
An infostealing malware campaign has been underway for at least three years, going completely unnoticed, Russian cybersecurity firm Kaspersky has revealed. The finding came after the company decided to take a closer look at the growing number of Linux-based attacks, which “can operate for years without being noticed by the…
Recent Posts
- Steam Machine and Steam Frame are coming ‘this summer’
- Valve says it’s ready to launch the Steam Machine this summer
- Best Buy slashes up to $400 off Apple tech in a limited-time sale — get AirPods, MacBooks, iPads and Apple Watches from $99.99
- The Instagram Plus subscription has officially launched
- Wired found code for an unreleased facial recognition feature in Meta’s AI app
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023