CronRAT Targets Linux eCommerce Servers

Linux systems are becoming a frequent target of cyberattacks. Of course, UNIX-based systems are much more secure compared to Windows, and this is one not all cybercriminals are able to develop and deploy such threats. One of the latest Linux-compatible malware families is dubbed CronRAT. As the name suggests, it is a Remote Access Trojan. But, what does it do?

How Does the CronRAT Go?

When the CronRAT infiltrates a computer successfully, it will enable its operators to modify specific files on the infected machine. The criminals seem to target mostly online shops, and they use the remote access to plant skimming code on payment and checkout pages. Although the servers of online stores are the primary target of the CronRAT for now, this is likely to change in the future.

One of the peculiar things about this malware is how it hides its code and components on the compromised machine. It creates a large number of cron jobs – Linux's scheduling system. However, they are all meant to run on a non-existent date – February 31st. The collection of the names of scheduled tasks is eventually deciphered to form a complicated script, which enables the execution of the CronRAT's modules. The Remote Access Trojan is able to operate in fileless mode, manage the file system, and receive remote commands from the attackers. Although it was initially able to evade certain Linux antivirus products, it is now detected by a large number of anti-malware engines. Administrators of Linux servers are advised to strengthen the security of their systems by using an up-to-date security application at all times.

November 29, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.