Security News > 2021 > January > Linux malware authors use Ezuri Golang crypter for zero detection
![Linux malware authors use Ezuri Golang crypter for zero detection](/static/build/img/news/alt/malware-statistics-2-scaled-medium.jpg)
Multiple malware authors are using the "Ezuri" crypter and memory loader to make their code undetectable to antivirus products.
According to a report released by AT&T Alien Labs, multiple threat actors are using Ezuri crypter to pack their malware and evade antivirus detection.
Although Windows malware have been known to deploy similar tactics, threat actors are now using Ezuri for infiltrating Linux environments as well.
Researchers Ofer Caspi and Fernando Martinez of AT&T Alien Labs noted after decrypting the AES-encrypted payload, Ezuri immediately passes the resulting code to the runFromMemory function as an argument without dropping malware files anywhere on the infected system.
During the last few months, Caspi and Martinez identified several malware authors that pack their samples with Ezuri.
Update 7-Jan-2020: Added statement from malware researcher and Ezuri creator, Bonicontro/TMZ..
News URL
Related news
- Ebury botnet malware infected 400,000 Linux servers since 2009 (source)
- Ebury Botnet Malware Compromises 400,000 Linux Servers Over Past 14 Years (source)
- New Cross-Platform Malware 'Noodle RAT' Targets Windows and Linux Systems (source)
- New Linux malware is controlled through emojis sent from Discord (source)