• Categories
    Category
  • Categories
    Category
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
News Comments FAQ Related Articles

A New Linux malware strain could morph into serious threat

3147

A new strain of malware that has been targeting Linux system is now being called as “ Linux/Shishiga” could pose as a dangerous security threat. The Eset disclosed about the threat that belongs to a new Lua family that has previously been overlooked on LuaBot malware.

The Linux/Shishiga uses four different protocols namely SSH, Telnet, HTTP and BitTorrent and Lua scripts for modularity says Detection Engineer Michal Malik, and Eset research team.

For those who don’ t know what is Lua? The Lua is a programming language characterized by its lightweight, embeddable nature scripting language. It supports procedural programming, object-oriented programming, functional programming, and data description.

The Linux/Shishiga uses the modules in the Lua language to make the malware more flexible. And it uses the brute force attack on weak credentials to get to the password list and uses the variety of different passwords to gain access.

The Shishiga is a binary packed with ultimate packer for executables (UPX) that has Shishiga adding data at the end of the packed file. After unpacking, it is linked to the Lua runtime library. It also combines the usage of Lua scripting language and linking it to Lua interpreter library.

" This means the authors either chose Lua as a scripting language for its ease of use," Malik said, " or inherited the code from another malware family, then decided to tailor it for each of the targeted architecture by linking statically the Lua library."

Despite the threat loomed in the air, the numbers of affected users were low and it clearly indicates that the work is still in progress. Eset warned the users that the count could increase rapidly and to stay vigilant at all times. Since it is using brute force attack on weak passwords, changing the passwords frequently could up the security against Shishiga.

To further barricade against this threat, especially if it is a data center, the users are warned not to use default Telnet and SSH credentials. According to Ansari, PCI/payments director at Schellman and company, " Defending against this category of threat requires the kind of defense in depth that security people have been talking about for a long time: aggressive patching, carefully reviewing log data, looking for suspicious files or processes, and rigorously tested incident response."

Tags:
muhammad
Author: 

Comments ( 0 )

No comments available

Add a comment

Frequently asked questions ( 5 )

Q

What happens if my antivirus program finds a virus?

A

Ideally, you want your antivirus software to clean the infected files or remove them completely.

How it does that will be dependent upon which program you have installed but, in general, most security software will try and move suspicious files into a quarantine area to swiftly eliminate the risk of an infection spreading. Once there, the software will probably give you the option of trying to remove the infection or just deleting it altogether.

Q

How much maintenance does antivirus software require?

A

Checking the status of your antivirus program daily – many offer a colour-coded scheme to alert you to any issues. If the program says everything is ok then all is good. Otherwise, delve deeper to learn what the problem is and then rectify it
Manually run an in-depth scan on a regular basis, maybe once a week, or use the functionality of the antivirus program itself to schedule a detailed scan, perhaps at a time when you are away from the machine
Checking that the program is fully up to date. This should happen automatically but I would advise confirming that all updates have been downloaded and installed from time to time

Q

Why did my new antivirus program just detect something the old one missed?

A

For the most part, antivirus programs rely on databases of virus signatures to identify malicious code on your computer.

Even though these are now largely stored in the cloud rather than on your hard drive, they are still vendor specific for the most part.

Thus, one company may have identified a threat that another has missed.

The chances of a reputable company not having a signature for a new piece of malware for any length of time is slim but it does happen in the short-term.

I’ve downloaded a new a

Q

What features should you look for in an antivirus program?

A

With hundreds of new malware strains being created every day, antivirus software is, for many people, the primary means of protecting both themselves and their computers from an ever-growing range of threats.

Q

Does a free antivirus program offer adequate protection?

A

here’s an old adage that says you get what you pay for and in the case of antivirus software that’s kind of true.

That’s not to say free antivirus programs should be dismissed out of hand though – some are actually very good and may well be sufficient for some people.

In terms of independent testing, AV-Test.org results over a period of time show that free antivirus programs do, on the whole, score lower than the paid-for alternatives in the marketplace and our own experience has taught us that free programs also tend to suffer from a lack of additional features, less than stellar support, an obsession with up-selling, or a combination of all three.

Related Tutorials in A New Linux malware strain could morph into serious threat

Related Tutorials in A New Linux malware strain could morph into serious threat

How to install Xrdp Server (Remote Desktop) on Oracle Linux 8.5
How to install Xrdp Server (Remote Desktop) on Oracle Linux 8.5
Oct 17, 2022
How to install and update OpenSSL on Debian 11.3
How to install and update OpenSSL on Debian 11.3
Oct 21, 2022
How to Install and Configure Mega in Linux
How to Install and Configure Mega in Linux
Jul 19, 2016
How to use Aureport command on Linux
How to use Aureport command on Linux
Nov 28, 2017
How to install Development tools on Linux
How to install Development tools on Linux
Jun 12, 2018
How to Install mod_ssl and SSL certificate on Oracle Linux
How to Install mod_ssl and SSL certificate on Oracle Linux
Dec 30, 2021
How to install Nextcloud on Ubuntu 22.04 version
How to install Nextcloud on Ubuntu 22.04 version
Jun 23, 2023
How to install ClipGrab in Linux
How to install ClipGrab in Linux
Jul 16, 2016

Related Forums in A New Linux malware strain could morph into serious threat

Related Forums in A New Linux malware strain could morph into serious threat

Linux
jayce class=
shasum command not found
May 5, 2017
Linux
stephan class=
How to list all samba users
Jan 12, 2018
pv command
muhammad class=
pvcreate command not found error
May 9, 2017
Linux
henry class=
Starting NFS daemon: rpc.nfsd: writing fd to kernel failed: errno 111 (Connection refused)
Apr 25, 2017
ifconfig command
jackbrookes class=
what is the location of the ifconfig program on your machine?
Jan 4, 2018
Linux
baseer class=
single command to apply setfacl for multiple user at a time
Jan 23, 2018
Linux
beulah class=
What does mean by 0 0 value in fstab file
Jan 2, 2018
CentOS
mason class=
Error getting authority: Error initializing authority: Could not connect: No such file or directory (g-io-error-quark, 1)
Nov 20, 2018

Related News in A New Linux malware strain could morph into serious threat

Related News in A New Linux malware strain could morph into serious threat

Anbox, the Android-to-Linux tool the developers have been waiting for
Anbox, the Android-to-Linux tool the developers have been waiting for
Apr 17, 2017
Linus Torvalds stops signing Linux kernel RC tarballs
Linus Torvalds stops signing Linux kernel RC tarballs
May 17, 2017
Capsule8 Launches Linux-Based Container Security Platform
Capsule8 Launches Linux-Based Container Security Platform
Feb 14, 2017
Symantec updates Management console product
Symantec updates Management console product
Nov 22, 2017
Latest Linux driver release feature seven AMD Vega
Latest Linux driver release feature seven AMD Vega
Mar 23, 2017
A Newer and a Faster Window Manager for Tina (Linux Mint 19.2)
A Newer and a Faster Window Manager for Tina (Linux Mint 19.2)
Apr 9, 2019
Microsoft makes its Azure App service now available on Linux Systems
Microsoft makes its Azure App service now available on Linux Systems
Sep 7, 2017
Docker friendly Alpine Linux gets hardened Node.js
Docker friendly Alpine Linux gets hardened Node.js
Apr 19, 2017
Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help Owen ?
How to add SSH key to my Gitlab account

I need to add the SSH key in my gitlab account. How to do so ????

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.