A relatively unknown but particularly stealthy technique to hide files on Linux hosts. On unhardened boxes, unprivileged users can conceal files from even the root user. Disk content remains in memory, hindering disk acquisition during forensic investigation. (1/7) 👇
HaxRob
@haxrob.net
Telco / mobile and IoT security. Surfing the information super highway one keystroke at a time. https://haxrob.net
Newer variants of the #BPFDoor has an interesting modification made that avoids detections looking for processes with raw sockets. The kernel reports SOCK_DGRAM rather then rather loud "SOCK_RAW". Here we have a sample found in the recent SK telco breach. (1/21)
#ESET research has identified #Linux malware samples, one of which we named #WolfsBane and attribute with high confidence to #Gelsemium. This 🇨🇳 China-aligned APT group, active since 2014, has not previously been publicly reported to use Linux malware. www.welivesecurity.com/en/eset-rese... 🧵(1/6)
Unveiling WolfsBane: Gelsemium’s Linux counterpart to Gelsevirine
ESET researchers analyzed previously unknown Linux backdoors that are connected to known Windows malware used by the China-aligned Gelsemium group, as well as to Project Wood.
welivesecurity.com
There is an interesting idea in here. Imagine a signalling firewall integrated in a way that detects SS7 / Diameter attacks originating from the GRX/IPX and informs the subscriber in real time to - offering immediate situational awareness to the customer.
New: I haven't owned a cellphone since ~2017. Telecom breaches, SIM swaps, SS7 attacks, location data selling, all reasons I don't have one. A startup selling a privacy-focused phone network to the US military is now offering it to the public. I tried it www.404media.co/i-dont-own-a...
I've lost count of the number of times I've found myself landing on nickvsnetworking.com when doing research. High quality content.
Nick vs Networking | Telco Network Engineering
nickvsnetworking.com
Hello world I guess? I post stuff to do with how #telecom networks work, then bitch about how they don't work. SIP/IMS, Signaling, Packet Core, Kamailio and Python - That kinda thing. Let's see how this goes!
GoblinRAT 👀 ✅ Tailored process name masquerading ✅ Port knocking ✅ Self destruct capability ✅ Overwrites disk artefacts with /dev/urandom ✅ Found on compromised gov infrastructure ✅ Linux / #golang ❌ IoCs but no samples anywhere to be found 😭