timb-machine / timb-machine/linux-malware

[Intel]: https://www.countercraftsec.com/blog/a-step-by-step-bpfdoor-compromise/

Open
#643 0 comments 0 reactions 1 assignee View on GitHub

@timb-machine is already working on this.

Since Apr 20, 2023.

confirmed ignore:tag:Auditd ignore:tag:T1005 ignore:tag:T1007 ignore:tag:T1021.002 ignore:tag:T1053.006 ignore:tag:T1057 ignore:tag:T1071.001 ignore:tag:T1083 ignore:tag:T1491 ignore:tag:T1543.002 ignore:tag:T1546.004 ignore:tag:T1562.001 ignore:tag:T1567 missing:tag:T1048 missing:tag:T1574.007
Dominant language
HTML
Stars
1.2k
Forks
95
PR merge metrics
No merged PRs in 30d

Description

Area

Malware reports

Parent threat

Persistence, Defense Evasion, Command and Control

Finding

https://www.countercraftsec.com/blog/a-step-by-step-bpfdoor-compromise/

Industry reference

attack:T1205.002:Socket Filters
attack:T1036:Masquerading
attack:T1070:Indicator Removal on Host
attack:T1205:Traffic Signaling
attack:T1573:Encrypted Channel
attack:T1106:Native API
attack:T1059.004: Unix Shell
attack:T1070.004:File Deletion
attack:T1036.004:Masquerade Task or Service
attack:T1070.006:Timestomp
uses:RedirectionToNull
uses:Non-persistentStorage
attack:T1036.005:Match Legitimate Name or Location
uses:ProcessTreeSpoofing
attack:T1562.004:Disable or Modify System Firewall

Malware reference

BPFDoor
/malware/binaries/BPFDoor
Unix.Backdoor.RedMenshen

Actor reference

No response

Component

Linux
Solaris

Scenario

No response

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.