Watchbog Linux Trojan
Watchbog is a newly observed trojan targeting Linux web servers running a variety of automation, database, mail, and project management products.
Summary
Watchbog is a newly observed trojan targeting Linux web servers running a variety of automation, database, mail, and project management products.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, Watchbog appears to be delivered directly to targets systems. Once a vulnerable system has been found, and its running services have been determined, Watchbog will deploy a number of publicly available exploits to gain access.
Once installed, Watchbog will download a set of commands from a Pastebin page; which, when executed, result in the installation of a Monero cryptocurrency miner. It then writes itself to several crontab files to maintain persistence.
For further information:
Update
Analysis of the latest variant of Watchbog has shown that it now includes a BlueKeep (CVE-2019-0708) exploitation module, raising the possibility of new Watchbog campaigns targeting vulnerable Windows systems.
Threat updates
| Date | Update |
|---|---|
| 25 Jul 2019 |
Analysis of the latest variant of Watchbog has shown that it now includes a BlueKeep (CVE-2019-0708) exploitation module, raising the possibility of new Watchbog campaigns targeting vulnerable Windows systems. |
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
CVE Vulnerabilities
Last edited: 14 February 2020 2:43 pm