Skidmap Linux Rootkit
Skidmap is a newly observed rootkit targeting Linux systems, primarily web servers, in order to enrol them into cryptocurrency mining botnets.
Summary
Skidmap is a newly observed rootkit targeting Linux systems, primarily web servers, in order to enrol them into cryptocurrency mining botnets.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how Skidmap is initially delivered, although the nature of its targets suggests its operators are manually identifying systems, gaining access, and dropping a preliminary script. This script is then executed to create a cron job to download and install Skidmap's main binary. Skidmap will then attempt to disable any SELinux security policies before deploying a backdoor to allow its operators access to any users present on the affected system.
Once this is done, Skidmap will check if the installed operating systems is Debian- or CentOS/RHEL-based, before unpacking and installing an unnamed cryptocurrency miner. It will then make several system calls to hide its files, and disguise network and CPU statistics to prevent detection when mining.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:58 pm