Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
New Linux rootkit, Syslogk uses magic packets to trigger backdoor

New Linux rootkit, Syslogk uses magic packets to trigger backdoorPost Views: 2
Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon-3.png Subscribe to Patreon to watch this episode.
Reading Time: 2 Minutes
A new Linux rootkit malware named ‘Syslogk’ is being used in attacks to hide malicious processes, using specially crafted “magic packets” to awaken a backdoor laying dormant on the device.
The malware is currently under heavy development, and its authors appear to base their project on Adore-Ng, an old open-source rootkit.

Syslogk can force-load its modules into the Linux kernel (versions 3.x are supported), hide directories and network traffic, and eventually load a backdoor called ‘Rekoobe.’ Using magic packets to load backdoorLinux rootkits are malware installed as kernel modules in the operating system. Once installed, they intercept legitimate Linux commands to filter out information that they do not want to be displayed, such as the presence of files, folders, or processes.

Similarly, when first loaded as a kernel module, Syslogk will remove its entry from the list of installed modules to evade manual inspection. The only sign of its presence is an exposed interface in the /proc file system.
https://www.bleepstatic.com/images/news/u/1220909/Code%20and%20Details/proc-listing.png
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking New Linux rootkit, Syslogk uses magic packets to trigger backdoor New Linux rootkit, Syslogk uses magic packets to trigger backdoorPost Views: 2 Premium Content https://www.blackhatethicalhacking.com/wp-content/uploads/2022/04/Patreon…
new Linux malware is ‘almost impossible’ to detect Should you be worried?The Syslogk rootkit is another example of highly-evasive malware for Linux systems added on top of the recently spotted Symbiote and BPFDoor, which both use the BPF system to monitor network traffic and dynamically manipulate it.

Linux systems aren’t prevalent among regular users, but they support some of the most valuable corporate networks out there, so threat actors are putting in the time and effort to develop custom malware for the architecture.

In the case of Syslogk, the project is in an early development phase, so whether or not it will become a widespread threat is uncertain at this time. However, considering its stealthiness, it will likely continue pushing new and improved versions.
See Also: Recon Tool: Domain Analyzer Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
The most dangerous development would be for Syslogk to release a version that supports more recent Linux kernel versions, which would greatly widen the targeting scope at once.
See Also: The Difference between Vulnerability Assessment and Pentesting
Source: bleepingcomputer.com Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch-1024x1024.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Header-Python-Packages-Blog-Final-Image-90x90.jpg PyPI package ‘keep’ mistakenly included a password stealer23 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/venom_superhero_movie_tom11_hardy-wallpaper-1920x1080-980x551-1-90x90.jpg This new Linux malware is ‘almost impossible’ to detect4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ran-download-33-1-e1639685560151-90x90.jpeg Black Basta Ransomware Teams Up with Malware Stalwart Qbot5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/InstallerFileTakeOver-Zero-Day-Security-Vulnerability-All-Windows-OS-Versions-90x90.jpg New ‘DogWalk’ Windows zero-day bug gets free unofficial patches6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/ipad_update_1200x675-90x90.jpg Security Fixes Won’t Require Full iOS Update in iOS 16, Will Be Installed Automatically1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Confluence-90x90.jpg Exploit released for Atlassian Confluence RCE bug, update now1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/be60-article-210907-confluence-body-text-90x90.png Critical Atlassian Confluence zero-day actively used in attacks2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/Microsoft-releases-solutions-for-a-zero-day-vulnerability-90x90.jpg New Windows Search zero-day added to Microsoft protocol nightmare2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/3266-90x90.jpg Hackers steal WhatsApp accounts using call forwarding trick2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/05/office-365-90x90.jpg Zero-Day ‘Follina’ Bug Lays Older Microsoft Office Versions Open to Attack2 weeks ago
The post New Linux rootkit, Syslogk uses magic packets to trigger backdoor first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video