Linux generals command Windows grunts in botnet battlefield
Malware discovered six years ago is still using Linux servers to command Windows botnets with a mutating virus
Computerworld Australia - Linux servers infected with a mutating virus are commanding huge Windows botnets six years after the malware was discovered, according to security researchers.
The Linux.RST.B virus infects the working directory/bin and its ELF (executable and linkable format) executable files. It can also create a back door by opening a socket and listening for a packet containing the attacker's origin and the command to be executed.
SophosLabs U.K. research director Billy McCourt said Linux boxes are valuable targets as botnet controllers because they are typically remain online as servers.
"Linux computers are very valuable to hackers. A bot army, similar to real armies, needs a general and infantry, [and] Linux boxes are often used as servers, which means they have a high uptime, essential for a central control point," McCourt said.
"A Windows computer, on the other hand, is found at home or as a desktop machine in an office, and these computers are regularly switched off, [which] makes them less attractive as controllers, but ideal for infantry, or zombies," he said.
"We run various honeypots," McCourt said. "As you might also expect, our Windows honeypots are attacked more frequently than our Linux ones, but Linux malware is far more interesting."
McCourt said the virus, discovered in February 2002, is unique among Linux malware because it can replicate across current distributions.
The veteran virus was trapped in an updated Linux server running a modified SSH (Secure Shell) daemon with a weak username and password to give the hacker easy access. New anti-malware signatures are developed by accessing logs that record the hackers'activities and downloaded files.
The virus usually infects servers by integrating into malware used by hackers in the attack. The attack is nothing new, according to McCourt, who said Windows hacking tools are often vectors for the W32.Parite-B virus.
Hackers typically favor Internet Relay Chat bots, SSH and File Transfer Protocol scanners, and User Datagram Protocol flooders, according to McCourt, and they occasionally attempt root access via various exploits.
Sophos senior security consultant Carole Theriault said Linux users can be lulled into thinking that their systems are bulletproof because malware rarely targets open-source systems.
"The number of malware in existence is around 350,000, and while only a teeny number of these target Linux, it seems as though hackers are taking advantage of this false sense of security," Theriault said.
"It was very surprising to see that a 6-year-old virus seems to be responsible for a large proportion of the malware collating in our Linux honeypot," she said.
Symantec Corp. recommend that affected users reinstall their Linux operating systems because it is impossible to ascertain the level of secondary threat exposure.
"The author of [Linux.RST.B] may have been able to use the threat to access the computer to make changes to it. Unless you can be absolutely sure that malicious activity has not been performed on the computer, we recommend completely reinstalling the operating system," Symantec stated on its security response site.
Sophos offers a free Linux.RST.B removal tool that it claims will purge the virus in systems free of other types of malware.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Consolidating SAP Applications to Linux on Power by IDC
- IDC studied a group of enterprises that had deployed SAP applications on IBM Power Systems servers running Linux server operating environments and had...
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will... All Linux and Unix White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Linux and Unix Webcasts