Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The shared object is injected in every process whose name does not contain substring gnome-session, dbus or pulseaudio... The injection is performed with a method similar to the one described on Blackhat 2001 by Shaun Clowes.
The dropper is obfuscated with the UPX packer... The readability of almost all character strings is hardened by a XOR encryption with a varying 8-bit key.
The shared object is injected in every process whose name does not contain substring gnome-session, dbus or pulseaudio... The injection is performed with a method similar to the one described on Blackhat 2001 by Shaun Clowes.
Then it decrypts the config file appended at the end of the binary... The procedure consists of mapping the binary into the memory and copying a relevant part to a buffer that is decrypted by AES with a 256bit key.
Immediately after start, the Trojan checks if it does not run in a virtualized environment... search for a substring "VBOX" and "VMware"... look for a substring "UML","PowerVM Lx86", "QEMU" or "IBM/S390" in /proc/cpuinfo... check an access to /proc/vz or /proc/bc... The presence of any of these signs leads to an early end of execution.
Immediately after start, the Trojan checks if it does not run in a virtualized environment... search for a substring "VBOX" and "VMware"... look for a substring "UML","PowerVM Lx86", "QEMU" or "IBM/S390" in /proc/cpuinfo... check an access to /proc/vz or /proc/bc... The presence of any of these signs leads to an early end of execution.
Intercepted data, statistics of bots execution, and command from C&C are all interpreted via a custom communication protocol based on AES encryption with 256bits keys combined with Base64 encoding
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux banking trojan referenced only as historical comparison regarding reuse of open-source rootkit/injection code.
Linux trojan focused on desktop compromise. It performs browser form-grabbing against Chromium, Chrome, and Firefox; establishes persistence via ~/.config/autostart/system-firewall.desktop; injects a shared object into processes and browsers; provides backdoor access through reverse shell, bind shell, and SOCKS5 proxy functionality; supports downloading/executing additional files; and includes anti-virtualization and anti-monitoring checks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.