New FontOnLake Linux malware used in targeted attacks
Full article327 words · extracted from therecord.media · click to collapse
Analysts from Slovak security firm ESET said they uncovered a new malware strain that targets Linux systems, which, based on current evidence, they believe was used in a handful of targeted attacks. Named FontOnLake, researchers said the malware's operators have been "particularly cautious" when deploying this tool in attacks. "The first known file of this malware family appeared on VirusTotal last May and other samples were uploaded throughout the year," said ESET malware analyst Vladislav Hrčka. "The location of the C&C server and the countries from which the samples were uploaded to VirusTotal might indicate that its targets include Southeast Asia," he added. At the time of writing, all the command-and-control (C&C) servers were down, which is reminiscent of typical attacks that target a small number of targets, with operators taking down infrastructure once their goals are met. But a more in-depth technical analysis of the FontOnLake malware is available in a PDF report released today by ESET, with a summary of the findings also available below: Additional analysis about this new stealthy malware is also available from Tencent, Avast, and Lacework, all of which have also encountered this new threat over the summer, under names like HCRootkit and Sutersu.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/new-fontonlake-linux-malware-used-in-targeted-attacks