EvilGnome.

Abarbarian

Acruncher
Joined
Sep 30, 2005
Messages
11,023
Reaction score
1,221
EvilGnome: A New Backdoor Implant Spies On Linux Desktop Users


EvilGnome: New Linux Spyware
Dubbed EvilGnome, the malware has been designed to take desktop screenshots, steal files, capture audio recording from the user's microphone as well as download and execute further second-stage malicious modules.


EvilGnome: Rare Malware Spying on Linux Desktop Users

"Linux desktop remains an unpopular choice among mainstream desktop users, making up a little more than 2% of the desktop operating system market share. This is in contrast to the web server market share, which consists of 70% of Linux-based operating systems. Consequently, the Linux malware ecosystem is plagued by financial driven crypto-miners and DDoS botnet tools which mostly target vulnerable servers.


This explains our surprise when in the beginning of July, we discovered a new, fully undetected Linux backdoor implant, containing rarely seen functionalities with regards to Linux malware, targeting desktop users."

Prevention and Response
We recommend to Linux users who want to check whether they are infected to check the “~/.cache/gnome-software/gnome-shell-extensions” directory for the “gnome-shell-ext” executable.



Luckily my Arch + Window Maker setup does not have the afore mentioned directory installed so this will not affect me. MINT and UBUNTU user here may have that directory installed so it worth while doing a quick check.


1563437525421.png

 

Ian

Administrator
Joined
Feb 23, 2002
Messages
19,873
Reaction score
1,499
I've not heard much about this, do you know how widespread it is?
 

Abarbarian

Acruncher
Joined
Sep 30, 2005
Messages
11,023
Reaction score
1,221
I've not heard much about this, do you know how widespread it is?

Not a clue. From the little I read it seems to be a sort of hacked version of some other nasty and still in a development state. I think it is out in the wild though and looks to have potential to pose a serious threat if not nipped in the bud.

A simple script + cron job to throw up an alert if the “gnome-shell-ext” executable shows up would be an easy fix for anyone who thought they may be at risk.

I posted as it is the first instance of a deliberate attempt to target linux desktop users.

1563528028169.png
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top