Skip the navigation
News

Linux generals command Windows grunts in botnet battlefield

Malware discovered six years ago is still using Linux servers to command Windows botnets with a mutating virus

By Darren Pauli
February 26, 2008 12:00 PM ET

Computerworld Australia - Linux servers infected with a mutating virus are commanding huge Windows botnets six years after the malware was discovered, according to security researchers.

The Linux.RST.B virus infects the working directory/bin and its ELF (executable and linkable format) executable files. It can also create a back door by opening a socket and listening for a packet containing the attacker's origin and the command to be executed.

SophosLabs U.K. research director Billy McCourt said Linux boxes are valuable targets as botnet controllers because they are typically remain online as servers.

"Linux computers are very valuable to hackers. A bot army, similar to real armies, needs a general and infantry, [and] Linux boxes are often used as servers, which means they have a high uptime, essential for a central control point," McCourt said.

"A Windows computer, on the other hand, is found at home or as a desktop machine in an office, and these computers are regularly switched off, [which] makes them less attractive as controllers, but ideal for infantry, or zombies," he said.

"We run various honeypots," McCourt said. "As you might also expect, our Windows honeypots are attacked more frequently than our Linux ones, but Linux malware is far more interesting."

McCourt said the virus, discovered in February 2002, is unique among Linux malware because it can replicate across current distributions.

The veteran virus was trapped in an updated Linux server running a modified SSH (Secure Shell) daemon with a weak username and password to give the hacker easy access. New anti-malware signatures are developed by accessing logs that record the hackers'activities and downloaded files.

The virus usually infects servers by integrating into malware used by hackers in the attack. The attack is nothing new, according to McCourt, who said Windows hacking tools are often vectors for the W32.Parite-B virus.

Hackers typically favor Internet Relay Chat bots, SSH and File Transfer Protocol scanners, and User Datagram Protocol flooders, according to McCourt, and they occasionally attempt root access via various exploits.

Sophos senior security consultant Carole Theriault said Linux users can be lulled into thinking that their systems are bulletproof because malware rarely targets open-source systems.

"The number of malware in existence is around 350,000, and while only a teeny number of these target Linux, it seems as though hackers are taking advantage of this false sense of security," Theriault said.

"It was very surprising to see that a 6-year-old virus seems to be responsible for a large proportion of the malware collating in our Linux honeypot," she said.

Symantec Corp. recommend that affected users reinstall their Linux operating systems because it is impossible to ascertain the level of secondary threat exposure.

"The author of [Linux.RST.B] may have been able to use the threat to access the computer to make changes to it. Unless you can be absolutely sure that malicious activity has not been performed on the computer, we recommend completely reinstalling the operating system," Symantec stated on its security response site.

Sophos offers a free Linux.RST.B removal tool that it claims will purge the virus in systems free of other types of malware.

Reprinted with permission from Computerworld Australia Story copyright 2006 Computerworld New Australia. All rights reserved.
Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Linux and Unix White Papers
Consolidating SAP Applications to Linux on Power by IDC
IDC studied a group of enterprises that had deployed SAP applications on IBM Power Systems servers running Linux server operating environments and had...
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
All Linux and Unix White Papers
Linux and Unix Webcasts
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
Virtualize Business-Critical Applications with Confidence
Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®...
All Linux and Unix Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs