George Zipperlen via plug on 29 Nov 2021 13:36:47 -0800


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] cronrat, containers



On 11/29/21 10:52 AM, jeffv wrote:
CronRAT: A New Linux Malware That's Scheduled to Run on February 31st

https://thehackernews.com/2021/11/cronrat-new-linux-malware-thats.html

Researchers have unearthed a new remote access trojan (RAT) for Linux
that employs a never-before-seen stealth technique that involves
masking its malicious actions by scheduling them for execution on
February 31st, a non-existent calendar day.

I'd call that a red flag, rather than stealth...

And crontab should be routinely hash verified.

--
George Zipperlen
george.zipperlen@mail.com

___________________________________________________________________________
Philadelphia Linux Users Group         --        http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug