Security News > 2021 > October > FontOnLake malware infects Linux systems via trojanized utilities

FontOnLake malware infects Linux systems via trojanized utilities
2021-10-10 17:16

A newly discovered malware family has been infecting Linux systems concealed in legitimate binaries.

FontOnLake has multiple modules that interact with one another and enable communication with malware operators, stealing sensitive data, and staying hidden on the system.

While ESET researchers found that the distribution method for FontOnLake is via trojanized application, they do not know how victims are lured to download the modified binaries.

"All the trojanized files are standard Linux utilities and serve as a persistence method because they are commonly executed on system start-up," Vladislav Hrčka, malware analyst and reverse engineer at ESET,.

The researchers discovered three custom backdoors written in C++ associated with the FontOnLake malware family, which provide operators remote access to the infected system.

The researchers believe that the author of FontOnLake is "Well versed in cybersecurity" and deactivated the C2 servers used in the samples found on VirusTotal once they learned of the upload. A puff of FontOnLake.


News URL

https://www.bleepingcomputer.com/news/security/fontonlake-malware-infects-linux-systems-via-trojanized-utilities/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Linux 18 380 1428 1130 696 3634