Bonum Certa Men Certa

ESET Finds Rootkits, Does Not Explain How They Get Installed, Media Says It Means "Previously Unknown Linux Backdoors" (Useful Distraction From CALEA and CALEA2)

posted by Roy Schestowitz on Nov 24, 2024

FUD watch: In the trailing citations, all the following links are a form of FUD (Fear, Uncertainty, Doubt), fear-mongering, and dramatisation. We must contextualise those.

Microsoft and ESET

TODAY we belatedly catch up with FUD [1-12] (after spending a week with family). The articles below are probably not the end of it, but it's all we've found so far.

So some of these articles are pure FUD and barely accessible (or probably skippable, as an associate said, due to either of these issues). We don't want to comment on each of these individually but instead remind people of ESET's collaborations with Microsoft. ESET habitually spreads anti-Linux 'studies' or 'research' at strategic (to Microsoft) times.

Looking at one "sample" of the FUD (not Microsoft-connected site, unlike some of the sites below), the associate said: "Rootkits are not a big deal [and] if the article does not give a hint about delivery. It seems like mostly a FUD campaign."

I had noticed the same and sought a second opinion. They also misuse the term "backdoor" and try to imply that Linux itself has back doors.

Why now? What's the point of this?

Well, there are real back doors being exploited by China and they're nothing to do with "Linux". The media mentioned them a few days ago, but it blamed "China" instead of those who put the back doors in there. As the associate said, "there's no mention of the real culprit, CALEA and CALEA2.

So what we have are real issues - an abundance of back doors, including the ones in Microsoft's products. But instead the media talks about "Linux", citing an Estonian partner of Microsoft.

"The Microsoft Effect," as the associate put it, implies that "all computers are insecure at some level so stay with Microsoft even though there are drastic differences in the levels of insecurity between Microsoft and non-Microsoft systems."

In one of the pieces below, "Microsoft mouthpieces try to play it up," our associate concluded.

While it's unwise to give visibility or publicity to bad pieces, adding some context to them and framing them as FUD can hopefully help.

Related/contextual items from the news:

  1. Gelsemium APT Hackers Attacking Linux Servers With New WolfsBane Malware

    A new Linux backdoor named WolfsBane has been recently uncovered by the ESET researchers, attributed to the Gelsemium advanced persistent threat (APT) group.

    This discovery marks the first public report of Gelsemium using Linux malware, signaling a shift in their operational strategy. WolfsBane is identified as the Linux counterpart of Gelsevirine, a known Windows malware used by Gelsemium.

  2. Researchers unearth two previously unknown Linux backdoors

    ESET researchers have identified multiple samples of two previously unknown Linux backdoors: WolfsBane and FireWood.

  3. Chinese APT Gelsemium Targets Linux Systems with New WolfsBane Backdoor

    The China-aligned advanced persistent threat (APT) actor known as Gelsemium has been observed using a new Linux backdoor dubbed WolfsBane as part of cyber attacks likely targeting East and Southeast Asia.

  4. Unveiling WolfsBane: Gelsemium’s Linux counterpart to Gelsevirine

    ESET researchers analyzed previously unknown Linux backdoors that are connected to known Windows malware used by the China-aligned Gelsemium group, and to Project Wood

  5. Chinese APT Gelsemium Deploys 'Wolfsbane' Linux Variant

    In a sign of the times, a backdoor malware whose ancestors date back to 2005 has morphed to target Linux systems.

    Two well-documented Chinese backdoors have recently been modified to operate on Linux systems.

  6. Chinese hackers target Linux with new WolfsBane malware

    A new Linux backdoor called 'WolfsBane' has been discovered, believed to be a port of Windows malware used by the Chinese 'Gelsemium' hacking group.

  7. China-linked hackers target Linux systems with new spying malware

    The group deployed Linux backdoors in a campaign likely focused on Taiwan, the Philippines, and Singapore.

  8. Chinese hackers exploit GNU/Linux with new WolfsBane malware
    ESET researchers uncover "WolfsBane," a GNU/Linux backdoor linked to the China-based Gelsemium group.
  9. Unmasking WolfsBane: Gelsemium’s New Linux Weapon

    ESET researchers have uncovered WolfsBane, a Linux cyberespionage backdoor attributed with high confidence to the Gelsemium advanced persistent threat (APT) group. This discovery is a major development, as it is the first public report of Gelsemium deploying Linux malware.

  10. Novel WolfsBane backdoor leveraged in Chinese attacks against Linux systems

    Attacks with Wolfsbane — which is suspected to be a port of Gelsemium's Windows malware — commence with the deployment of the 'cron' dropper delivering the KDE desktop component-spoofing launcher, which deactivates SELinux and alters user configuration files before triggering the privacy malware component that has file operation, data theft, and system manipulation command support, an analysis from ESET revealed. Also discovered to be leveraged by Gelsemium in targeting Linux systems was the FireWood backdoor, which features shell command execution, file operation, and data exfiltration capabilities. However, such a tool may have been shared with other Chinese APTs. Mounting adoption of endpoint detection and response tools, as well as Microsoft's default deactivation of Visual Basic for Applications macros may have prompted increased utilization of Linux malware, according to ESET. "Consequently, threat actors are exploring new attack avenues, with a growing focus on exploiting vulnerabilities in internet-facing systems, most of which run on Linux," ESET added.

  11. In Other News: Nvidia Fixes Critical Flaw, Chinese Linux Backdoor, New Details in WhatsApp-NSO Lawsuit
  12. Linux devices hit with even more new malware, this time from Chinese hackers

    Chinese hackers have built new all-in-one malware to target Linux devices, a new report from cybersecurity researchers ESET, have said.

Other Recent Techrights' Posts

Windows Has Now Fallen to Rather Ridiculous 3% "Market Share" in Iraq (Windows Was Measured at 100% Back in 2010)
Iraq is not a place where Windows can make a comeback
New USPTO Memo Makes Fighting Patent Trolls Even Harder
The U.S. Patent and Trademark Office (USPTO) just made a move that will protect bad patents at the expense of everyone else
An "EU OS" Would Need European Components
There are many European (or Europe-led) distros of GNU/Linux. EU OS developers ought to look at those.
 
Cellphones (Mobile Phones) in Classrooms
A recent study confirmed that people's intelligence has dropped in recent years/decades
Is the FSF Being 'Trolled' by Microsofters Pushing C# (Microsoft)?
Who stands to benefit from training people to use and spread Microsoft?
Matthew J. Garrett is "Former Microsoft Researcher", According to Microsoft's Serial Strangler
Their argument is something along the lines of, "what Roy published damaged my career prospects, so I want Roy to pay me...
Links 24/03/2025: Political Catchup and Environmental Concerns
Links for the day
Gemini Links 24/03/2025: Working With Music and Unconscious Influence
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, March 23, 2025
IRC logs for Sunday, March 23, 2025
Critics of IBM's Strategy Aren't Racists, But...
the situation is saddening as it serves to obscure the severity of the problem
Mauritania: Windows Falls to All-Time Low of 6% (It Used to be Over 99%)
Windows is 0% in mobile
Outline of Open Source Initiative Coverage to Come (Now That Consensus is Changing)
Policing Wikipedia and attacking critics is not a sustainable strategy
Gemini Links 23/03/2025: "Connor of the Cats" and CSS Naked Day
Links for the day
Links 22/03/2025: Science and Antoine Beaupré on "Losing the War for the Free Internet"
Links for the day
We Probably Served Close to 100 Million Gemini Requests
Many of these requests probably came from bots, but it's hard to distinguish (to block them) ... This coming summer Gemini Protocol will turn 6
Just Because Microsoft Resents Techrights Doesn't Mean SLAPPs Will Silence Techrights
To confront lies the best solution is to speak truth
Windows at New Low Levels in Madagascar (Population About 33 Million)
Madagascar does not need Microsoft
Slop Images Are Bad Optics, Including for Perl.org
Slop devalues one's genuine work
What Happened to the Open Source Initiative (OSI) Elections: Proprietary Software Companies in Control, the Scandals Cannot be Hidden Anymore
We'll talk about it later this month and next month
Slopwatch: Fake News About Security Using LLMs That Make Fake 'Articles' About "Linux" (With Slop for Images)
This cannot end well
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, March 22, 2025
IRC logs for Saturday, March 22, 2025
Gemini Links 22/03/2025: "Ukay Ukay", Microplastics in Tea, Jujutsu, and More
Links for the day
Links 22/03/2025: Johor Flooded, Ador Traps Young Musicians With Contract
Links for the day
[Video] Richard Stallman on What Patents Would Have Done to Music (Covered by Copyrights)
Our WebM version can be played using Free software, independently of the availability of Invidious mirrors
Our IRC Community Turns 17 Very Shortly
A few years from now our IRC community will turn 20
Microsoft Destroys and Exploits, It Does Not Create
A race to nowhere
Linux Foundation Buys Misleading Puff Pieces About Itself, Earns Some LLM Slop to Accompany the PR (Openwashing and Propaganda as a Service, With the Brand "Linux" Needlessly Borrowed)
Isn't it funny that after the "LF" (misusing the brand "Linux") flooded the Web with press releases and fake articles (that it had paid for) it now gets some LLM slop doing the same?
It's About So Much More Than 2 Microsofters, It's About Freedom to Speak About Crimes at Microsoft
Suffice to say, if some people related to our professional field attack women and get arrested for it, then there's nothing immoral about relaying this information
Links 22/03/2025: Social Security Attacks and More Attacks on the Press
Links for the day
Gemini Links 22/03/2025: INTERPOL, DDoS by "Hey Hi" Hype, and RSS/Feed Readers
Links for the day
Links 22/03/2025: Alzheimer Research and Mega-breaches in the US
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, March 21, 2025
IRC logs for Friday, March 21, 2025