New Linux malware combines unusual stealth with a full suite of capabilities

'Researchers this week unveiled a new strain of Linux malware that's notable for its stealth and sophistication in infecting both traditional servers and smaller Internet-of-things devices. Dubbed Shikitega by the AT&T Alien Labs researchers who discovered it, the malware is delivered through a multistage infection chain using polymorphic encoding. It also abuses legitimate cloud services to host command-and-control servers. These things make detection extremely difficult. "Threat actors continue to search for ways to deliver malware in new ways to stay under the radar and avoid detection," AT&T Alien Labs researcher Ofer Caspi wrote. "Shikitega malware is delivered in a sophisticated way, it uses a polymorphic encoder, and it gradually delivers its payload where each step reveals only part of the total payload. In addition, the malware abuses known hosting services to host its command and control servers."' -- source: https://arstechnica.com/information-technology/2022/09/new-linux-malware-com... Cheers, Peter -- Peter Reutemann Dept. of Computer Science University of Waikato, NZ +64 (7) 858-5174 (office) +64 (7) 577-5304 (home office) https://www.cs.waikato.ac.nz/~fracpete/ http://www.data-mining.co.nz/

On Sat, 10 Sep 2022 21:32:21 +1200, Peter Reutemann quoted:
'It also abuses legitimate cloud services to host command-and-control servers.'
I’ve often wondered about the distinction between “command” and “control”, and why you need to mention both. Isn’t it enough to say it’s a “command” server? Or a “control” server?

I presume, it is just reusing a military term: https://en.wikipedia.org/wiki/Command_and_control "Military exercise of authority by a commanding officer over assigned forces." Cheers, Peter -- Peter Reutemann Dept. of Computer Science University of Waikato, NZ +64 (7) 858-5174 (office) +64 (7) 577-5304 (home office) http://www.cs.waikato.ac.nz/~fracpete/ http://www.data-mining.co.nz/ Sep 11, 2022 11:04:32 Lawrence D'Oliveiro <ldo(a)geek-central.gen.nz>:
On Sat, 10 Sep 2022 21:32:21 +1200, Peter Reutemann quoted:
'It also abuses legitimate cloud services to host command-and-control servers.'
I’ve often wondered about the distinction between “command” and “control”, and why you need to mention both. Isn’t it enough to say it’s a “command” server? Or a “control” server? _______________________________________________ wlug mailing list -- wlug(a)list.waikato.ac.nz | To unsubscribe send an email to wlug-leave(a)list.waikato.ac.nz Unsubscribe: https://list.waikato.ac.nz/postorius/lists/wlug.list.waikato.ac.nz

On Sat, 10 Sep 2022 23:47:52 +0000 (UTC), Peter Reutemann wrote:
I presume, it is just reusing a military term:
https://en.wikipedia.org/wiki/Command_and_control
"Military exercise of authority by a commanding officer over assigned forces."
So, not “command-and-controlling officer”?
participants (3)
-
Lawrence D'Oliveiro
-
Peter Reutemann
-
Peter Reutemann