• Home
  • Top News
  • Entertainment
  • Economy
  • World
  • Sports
  • Contact Form
Facebook Twitter Instagram
Facebook Twitter Instagram
celebritybeautybuzz.com
  • Home
  • Top News
  • Entertainment
  • Economy
  • World
  • Sports
  • Contact Form
celebritybeautybuzz.com
Home ยป Breaking News: Introducing Celebrity Beauty Buzz – Unveiling the New SprySOCKS Linux Malware in Cyber Espionage Attacks
Technology

Breaking News: Introducing Celebrity Beauty Buzz – Unveiling the New SprySOCKS Linux Malware in Cyber Espionage Attacks

John SpearsBy John SpearsSeptember 19, 2023No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email

Title: Chinese Hacker ‘Earth Lusca’ Targets Government Agencies with New Linux Backdoor ‘SprySOCKS’

In a recent cybersecurity development, Chinese hacker group ‘Earth Lusca’ has been identified as the perpetrator behind attacks on government agencies around the world. The group has unleashed a new Linux backdoor called ‘SprySOCKS’ to target key government entities in Southeast Asia, Central Asia, and the Balkans, alongside other regions.

SprySOCKS is believed to have originated from the Trochilus open-source Windows malware, but it has been specifically modified to operate on Linux systems. By combining features of RedLeaves and Derusbi malware, Earth Lusca has created a potent tool for breaching the security of targeted organizations.

To gain initial access, the Chinese hacker group exploits n-day vulnerabilities and then drops Cobalt Strike beacons for remote access. As a variant of the Linux ELF injector ‘mandibule,’ SprySOCKS deploys a loader named ‘libmonitor.so.2.’ This loader allows SprySOCKS to function seamlessly within Linux systems.

Of particular concern is SprySOCKS’ utilization of the high-performance networking framework ‘HP-Socket’ and AES-ECB encryption for command and control (C2) communications. This sophisticated approach ensures that Earth Lusca’s malicious activities remain hidden while they collect system information, establish an interactive shell, manage network connections, configure SOCKS proxies, and perform basic file operations.

To further obfuscate their activities, SprySOCKS generates a unique client ID using a combination of MAC address and CPU features. This ensures that each attack appears distinct and difficult to trace back to Earth Lusca.

The ongoing development of SprySOCKS is evident through two known versions – v1.1 and v1.3.6 – indicating that Earth Lusca remains invested in refining and expanding their cyber capabilities.

Security experts are urging organizations, especially those operating within the government sector, to prioritize the application of security updates. This proactive approach can help prevent initial compromises from Earth Lusca’s SprySOCKS backdoor, thwarting potential attacks before they gain traction.

As the threat landscape continues to evolve, vigilance and timely implementation of security measures become crucial. By staying one step ahead, organizations can ensure the safety of their sensitive data and protect themselves from the growing threat presented by Earth Lusca and its latest creation, SprySOCKS.

John Spears

“Infuriatingly humble tv expert. Friendly student. Travel fanatic. Bacon fan. Unable to type with boxing gloves on.”

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
John Spears

"Infuriatingly humble tv expert. Friendly student. Travel fanatic. Bacon fan. Unable to type with boxing gloves on."

Related Posts

Eufys New Security Cameras to Include Cross-Camera People Tracking

September 27, 2023

Eddy Cue, Apples Executive, to Testify in Google Antitrust Case

September 26, 2023

How Microsofts AI Advancements Impact Your Windows Laptop

September 23, 2023

Leave A Reply Cancel Reply

Recent Posts

  • 2023 Ryder Cup: Complete TV Schedule, Team Info and More
  • Germany Implements Border Checks with Poland and Czech Republic
  • Catch a Glimpse of the Harvest Supermoon – Celebrity Beauty Buzz
  • Beauty Swirl: Unveiling the Charm of Celebrities
  • Eufys New Security Cameras to Include Cross-Camera People Tracking

Recent Comments

No comments to show.

Archives

  • September 2023
  • August 2023
  • July 2023

Categories

  • Business
  • Entertainment
  • Health
  • Science
  • Sports
  • Technology
  • Top News
  • World
Facebook Twitter Instagram Pinterest
  • Privacy Policy
  • DMCA
  • Contact Form
  • About Us
© 2023 ThemeSphere. Designed by ThemeSphere.

Type above and press Enter to search. Press Esc to cancel.