New advanced linux trojan/rootkit just discovered, servers still active

127 views
Skip to first unread message

dro...@gmail.com

unread,
May 31, 2019, 11:57:32 AM5/31/19
to qubes-users
They are calling it HiddenWasp. Currently undetectable by all anti-virus platforms, who are now scrambling to update their software.

https://arstechnica.com/information-technology/2019/05/advanced-linux-backdoor-found-in-the-wild-escaped-av-detection/

Interesting read. Should be interesting which linux distro's got infected.

dro...@gmail.com

unread,
May 31, 2019, 12:20:21 PM5/31/19
to qubes-users

Sphere

unread,
Jun 4, 2019, 5:40:28 AM6/4/19
to qubes-users
This one shouldn't be a problem so long as dom0 is not compromised.
Also nice that we can just block 103.206.123[.]13 and 103.206.122[.]245

Also, this thing doesn't even survive a reformat so yeah nothing much to worry about (not unless they also aim to persist in your routers and other network devices).

Yethal

unread,
Jun 4, 2019, 4:10:01 PM6/4/19
to qubes-users
Based on the fact that it adds itself to /etc/rc.local for persistence it wouldn't even survive qube reboot
Reply all
Reply to author
Forward
0 new messages