DinodasRAT Linux Version Used in Asian Countries

Security researchers revealed the emergence of a Linux iteration of DinodasRAT, a versatile backdoor malware, spotted in the wild targeting regions including China, Taiwan, Turkey, and Uzbekistan.

DinodasRAT, also known as XDealer, operates in C++ and possesses the capability to extract a broad spectrum of sensitive data from compromised systems.

In October 2023, researchers uncovered a cyber espionage campaign, termed Operation Jacana, targeting a governmental entity in Guyana using the Windows version of this malware. Newer reports reports highlight a shift in threat activity to DinodasRAT, codenamed Earth Krahang, targeting various government bodies worldwide since 2023.

DinodasRAT Linked to Chinese APTs

Attributed mainly to China-associated threat actors like LuoYu, DinodasRAT's Linux variant (V10) was first detected in early October 2023, with earlier variants dating back to July 2021 (V7). A newer version (V11) was identified in November 2023.

Primarily tailored for Red Hat-based distributions and Ubuntu Linux, upon execution, DinodasRAT establishes persistence via SystemV or SystemD startup scripts, communicating with a remote server over TCP or UDP for command retrieval.

This backdoor is equipped to carry out file operations, alter command-and-control addresses, manage running processes, execute shell commands, update itself, and self-destruct. It employs tactics to evade detection, including encryption of C2 communications using the Tiny Encryption Algorithm (TEA).

Researchers notes DinodasRAT's focus on gaining and retaining access to Linux servers rather than reconnaissance, facilitating complete control for data exfiltration and espionage.

Check Point's analysis reveals DinodasRAT's origins in the open-source project SimpleRemoter, evolving from Gh0st RAT. The Linux variant, named Linodas, features capabilities like multi-threaded system monitoring, auxiliary modules for interfering with system binaries, and a filter module acting as a proxy for controlling output from original binaries to evade detection and gather information from hosts.

April 2, 2024
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.