Security News > 2022 > June > New Symbiote malware infects all running processes on Linux systems

New Symbiote malware infects all running processes on Linux systems
2022-06-09 12:00

A newly discovered Linux malware known as Symbiote infects all running processes on compromised systems, steals account credentials, and gives its operators backdoor access.

After injecting itself into all running processes, the malware acts as a system-wide parasite, leaving no identifiable signs of infection even during meticulous in-depth inspections.

Symbiote uses the BPF hooking functionality to sniff network data packets and to hide its own communication channels from security tools.

Instead of having the typical form of an executable, Symbiote is a shared object library that gets loaded into running processes using the LD PRELOAD directive to gain priority against other SOs.

To hide its malicious network activity on the compromised machine, Symbiote scrubs connection entries it wants to hide, performs packet filtering via BPF, and removes UDP traffic to domain names in its list.

This stealthy new malware is primarily used for automated credential harvesting from hacked Linux devices by hooking the "Libc read" function.


News URL

https://www.bleepingcomputer.com/news/security/new-symbiote-malware-infects-all-running-processes-on-linux-systems/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Linux 11 64 2337 1502 67 3970