article thumbnail

perfctl: A Stealthy Malware Targeting Millions of Linux Servers

Aqua Security

In this blog post, Aqua Nautilus researchers aim to shed light on a Linux malware that, over the past 3-4 years, has actively sought more than 20,000 types of misconfigurations in order to target and exploit Linux servers. If you have a Linux server connected to the internet, you could be at risk.

Malware 98
article thumbnail

PYSA Ransomware Gang adds Linux Support

Lacework

Key Take Aways The first Linux version of ChaChi, a Golang based DNS tunneling backdoor, was recently observed on VirusTotal. The malware is configured to use domains associated with ransomware actors known as PYSA, aka Menipoza Ransomware Gang. The post PYSA Ransomware Gang adds Linux Support appeared first on Lacework.

Linux 134
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Trending Sources

article thumbnail

Hunting Rootkits with eBPF: Detecting Linux Syscall Hooking Using Tracee

Aqua Security

Tracee is an open source runtime security and forensics tool for Linux that is powered by eBPF and is more optimized for secure tracing. In this blog, we’ll explore the ways to control eBPF events and examine a case of using a BPF event to capture rootkits, a sophisticated type of malware that lives in the kernel space.

Linux 142
article thumbnail

Hadooken Malware Targets Weblogic Applications

Aqua Security

Aqua Nautilus researchers identified a new Linux malware targeting Weblogic servers. When Hadooken is executed, it drops a Tsunami malware and deploys a cryptominer. In this blog, we explain the malware, its components, and how we detected

Malware 98
article thumbnail

Kinsing Malware Hides Itself as a Manual Page and Targets Cloud Servers

Tenable

One of the most common cryptomining threats for cloud environments is the Kinsing malware. Kinsing is a notorious malware family active for several years, primarily targeting Linux-based cloud infrastructure. The Kinsing malware uses different locations to stay undetected and hides itself as a system file.

Malware 127
article thumbnail

Go deeper: Linux runtime visibility meets Wireshark

Aqua Security

Aqua Tracee is an open source runtime security and forensics tool for Linux, built to address common Linux security issues. Some alternative use cases which Tracee can be used for are dynamic malware analysis, system tracing, forensic investigations, and more.

Linux 98
article thumbnail

Detecting eBPF Malware with Tracee

Aqua Security

eBPF is a popular and powerful technology embedded in the Linux kernel. Lately, we have seen a rise in the number of eBPF based tools used for malicious goals such as rootkits ( ebpfkit, TripleCross ) and malwares ( pamspy ). It is widely used by many security tools for monitoring kernel activity to detect and protect organizations.

Malware 96