EvilGnome Linux Backdoor
EvilGnome is a backdoor targeting vulnerable Linux systems. Despite having similarities with malware employed by the Gamaredon Group, an advanced persistent threat operating in Eastern Europe, EvilGnome is targeting users globally.
Summary
EvilGnome is a backdoor targeting vulnerable Linux systems. Despite having similarities with malware employed by the Gamaredon Group, an advanced persistent threat operating in Eastern Europe, EvilGnome is targeting users globally.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, EvilGnome appears to be distributed as a self-extracting archive script disguised as a GNOME Linux graphical shell extension. When downloaded, it decompresses and launches modules to maintain persistence and collect information.
Once installed, EvilGnome will connect to a command and control (C2) server over TCP port 3346 using Secure Shell and await further commands. By default, EvilGnome has five function modules:
- ShooterFile - reads and transfers newly created files
- ShooterImage - captures screenshots
- ShooterKey - unimplemented, but likely to be a key logging module
- ShooterPing - receives new commands from the C2 server
- ShooterSound - captures microphone audio
Remediation steps
| Type | Step |
|---|---|
|
The following steps can be used to identify and remove EvilGnome's persistence mechanisms.
Additionally, to prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:49 pm