This sneaky Linux malware went undetected for years, and is using all-new attack tactics
A novel piece of Linux malware, which grants its operators the ability to remotely access the compromised device, has been hiding in plain sight for more than two years now, experts have warned.
Stroz Friedberg, which discovered the malware and wrote an in-depth explainer, said the malware is called “sedexp”, and has been evading detection since 2022.
While granting the attackers remote access to the vulnerable endpoint is important, it’s not this malware’s unique property. Instead, it’s the way it remained hidden for more than two years, and made sure most antivirus solutions didn’t detect it.
Udev rules abused
As per the report, sedexp went under the radar by using udev rules.
“At the time of this writing, the persistence technique used (udev rules) is not documented by MITRE ATT&CK,” the researchers note.
Udev is a device manager for the Linux kernel, responsible for managing device nodes in the /dev directory. It dynamically creates and removes device nodes based on the devices connected to the system, such as USB drives, printers, and network interfaces. It also makes sure that each node gets the right driver loaded into memory.
Udev rules, on the other hand, are text configurations that tell the device manager how to work different devices or events. To run the malware, and make sure it remains hidden, it adds a specific rule to udev, the researchers explained. Finally, the malware names its process ‘kdevtmpfs’, the same as another, legitimate process, making detection even harder.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Stroz Friedberg believes this piece of malware has been used since at least 2022, and found it in numerous online sandboxes, none of which triggered any antiviruses. The researchers believe the malware was used to hide a credit card skimmer.
Via BleepingComputer
More from TechRadar Pro
A novel piece of Linux malware, which grants its operators the ability to remotely access the compromised device, has been hiding in plain sight for more than two years now, experts have warned. Stroz Friedberg, which discovered the malware and wrote an in-depth explainer, said the malware is called “sedexp”,…
Recent Posts
- Amazon’s new Proteus warehouse robot is fully autonomous
- Let us filter AI slop, you cowards
- AI leaders call for tougher protections against AI-aided bioweapons
- 5 Best Smart Speakers (2026): Alexa, Google Assistant, Siri
- I’m an outdoors expert — here are 9 easy-pitch tents I’d recommend for a fuss-free camping trip
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023