this post was submitted on 10 Dec 2023
32 points (94.4% liked)

Hacker News

1770 readers
1 users here now

This community serves to share top posts on Hacker News with the wider fediverse.

Rules0. Keep it legal

  1. Keep it civil and SFW
  2. Keep it safe for members of marginalised groups

founded 1 year ago
MODERATORS
 

There is a discussion on Hacker News, but feel free to comment here as well.

top 2 comments
sorted by: hot top controversial new old
[–] [email protected] 4 points 6 months ago (1 children)

This is the best summary I could come up with:


Stealthy and multifunctional Linux malware that has been infecting telecommunications companies went largely unnoticed for two years until being documented for the first time by researchers on Thursday.

Researchers from security firm Group-IB have named the remote access trojan “Krasue,” after a nocturnal spirit depicted in Southeast Asian folklore “floating in mid-air, with no torso, just her intestines hanging from below her chin.” The researchers chose the name because evidence to date shows it almost exclusively targets victims in Thailand and “poses a severe risk to critical systems and sensitive data given that it is able to grant attackers remote access to the targeted network.

It then proceeds to hook the syscall, network-related functions, and file listing operations, thereby obscuring its activities and evading detection.

Rootkits are a type of malware that hides directories, files, processes, and other evidence of its presence to the operating system it’s installed on.

By hooking legitimate Linux processes, the malware is able to suspend them at select points and interject functions that conceal its presence.

Intercepting the kill() syscall also allows the trojan to survive Linux commands attempting to abort the program and shut it down.


The original article contains 288 words, the summary contains 192 words. Saved 33%. I'm a bot and I'm open source!

[–] [email protected] 2 points 6 months ago* (last edited 6 months ago)

Damn republicans, trynna come after our kill()