this post was submitted on 11 Dec 2023
188 points (97.0% liked)

Technology

58387 readers
4399 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

Stealthy Linux rootkit found in the wild after going undetected for 2 years::Krasue infects telecom firms in Thailand using techniques for staying under the radar.

you are viewing a single comment's thread
view the rest of the comments
[–] raspberriesareyummy 90 points 9 months ago* (last edited 9 months ago) (2 children)

Zero useful info: what is the attack vector / vulnerability exploited? Without that info, this is useless

[–] anamethatisnt 60 points 9 months ago* (last edited 9 months ago) (2 children)
[–] [email protected] 29 points 9 months ago (1 children)

The only thing I know runs that kernel version is my Wii because it needs an old kernel for ppc32 support

load more comments (1 replies)
[–] raspberriesareyummy 2 points 9 months ago

Now that is helpful information - current distros being on 6.x and whatnot... Thanks!

[–] [email protected] 30 points 9 months ago (1 children)

From the article:

The researchers have so far been unable to determine precisely how Krasue gets installed.

So no one knows yet. But I feel that the existence of malware in the wild is newsworthy, even if we don't know how it got there. Regardless, you and I probably don't have to worry about it unless you're a Thai telecom.

[–] raspberriesareyummy 1 points 9 months ago

And unless we run a 3.x kernel as another commentor pointed out...