Linux malware, CronRAT, is hiding in a cron job with incorrect dates

Researchers from the Dutch company Sansec have discovered a new malware for Linux CronRAT. It is a Remote Access Trojan (RAT) that escapes detection by hiding in tasks scheduled to run on the nonexistent day of February 31st.

The malware is called CronRAT and mainly attacks online stores, allowing cybercriminals to steal bank card data and deploy web skimmers on Linux servers (דאס איז, to carry out the so-called MageCart attacks). צום באַדויערן, many security solutions simply do notseeCronRAT due to a number of peculiarities in its operation.

CronRAT abuses Linux’s task scheduling system, cron, which allows tasks to be scheduled to run on non-existent calendar days such as February 31st. אין דעם פאַל, the cron system accepts such dates if they have a valid format (even if the day does not exist in the calendar), but such a scheduled task will simply not be completed.

By taking advantage of this feature, CronRAT remains virtually invisible. In their report, Sansec experts say that the malware hides acomplex bash programin the names of such scheduled tasks.

CronRAT adds a number of tasks to the crontab with an interesting date specification: 52 23 31 2 3. These lines are syntactically correct but will generate a run time error when executed. אָבער, this will never happen, since the launch of such tasks is generally scheduled for February 31st.

The actual payload is obfuscated with multiple compression levels and Base64. The researchers say the code includes commands for self-destruct, time modulation, and a custom protocol that allows it to communicate with a remote server.

CronRAT code

CronRAT decoder

The malware is known to communicate with the C&C סערווער (47.115.46.167) usingan exotic Linux kernel function that provides TCP communication via a file.” אין צוגאב, the connection is made over TCP over port 443 using a fake banner for the Dropbear SSH service, which also helps the Trojan go unnoticed.

As mentioned above, CronRAT was found in many online stores around the world, where it was used to implement special skimmer scripts that steal payment card data. Sansec describes the malware asa serious threat to Linux-based eCommerce servers.

The problem is aggravated by the fact that CronRAT is almost invisible to security solutions. According to VirusTotal, 12 antivirus solutions failed to process the malicious file at all, און 58 found no threat in it.

Let me remind you that we also talked about another Linux malware פאָנטאָנלאַקע that is used in targeted attacks.

העלגאַ סמיט

איך בין שטענדיק אינטערעסירט אין קאָמפּיוטער וויסנשאַפֿט, ספּעציעל דאַטן זיכערהייט און די טעמע, וואס הייסט היינט-צו-טאג "דאַטן וויסנשאַפֿט", זינט מיין פרי טינז. איידער איר קומען אין די ווירוס באַזייַטיקונג מאַנשאַפֿט ווי רעדאַקטאָר-אין-ראשי, איך געארבעט ווי אַ סייבערסעקוריטי מומחה אין עטלעכע קאָמפּאַניעס, אַרייַנגערעכנט איינער פון אַמאַזאָן ס קאָנטראַקטאָרס. אן אנדער דערפאַרונג: איך האָבן געלערנט אין Arden און רידינג אוניווערסיטעטן.

לאָזן אַ ענטפער

דער פּלאַץ ניצט Akismet צו רעדוצירן ספּאַם. לערנען ווי דיין באַמערקונג דאַטן זענען פּראַסעסט.

צוריק צו שפּיץ קנעפּל