HiddenWasp Linux Remote Access Trojan
HiddenWasp is a newly observed remote access trojan that makes extensive use of code from older open-source malware such as Azazel, Elknot, and Mirai.
Summary
HiddenWasp is a newly observed remote access trojan that makes extensive use of code from older open-source malware such as Azazel, Elknot, and Mirai.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, HiddenWasp appears to be delivered as a secondary payload. An unknown dropper will execute a bash script on a target system, which will connect to an attacker-controlled file server to download and deploy HiddenWasp.
Once installed, HiddenWasp will initiate a connection with a command and control (C2) server. All communications between HiddenWasp and the C2 server are encrypted using a hard-coded RC4 key. It will then alter environment variables to maintain persistence and disguise it's actions, before hooking into several functions in order to execute arbitrary code or extract data.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 11 January 2022 9:46 am