YIKES: Fancy Bear Linux Rootkit

Stu Sjouwerman | Aug 14, 2020

Vladimir_Putin_GRUHeads-Up! The CyberWire staff wrote: "The US National Security Agency and Federal Bureau of Investigation yesterday issued a joint alert concerning a new malware toolset operated by Russia's military intelligence service, GRU. The advisory describes Drovorub, malware deployed by APT28, which of course is Fancy Bear. Drovorub is a multifunctional "Linux malware toolset consisting of an implant coupled with a kernel module rootkit, a file transfer and port forwarding tool, and a Command and Control (C2) server." So far it seems that Fancy Bear is Drovorub's only user. Both NSA and the Bureau offer advice on how to detect the malware and protect against it. The warning is being taken seriously: as the Register puts it, four words you don't want to see together are "Fancy Bear Linux rootkit."

Kaspersky researchers have published an update on the activities of "CactusPete" (also known as Karma Panda), a Chinese APT that's using a new form of the Bisonal backdoor against defense and banking targets in Eastern Europe. Capability of handling Cyrillic script suggests that its activities extend east through Ukraine, Belarus, and Russia. It's a cyberespionage campaign, but it may also represent reconnaissance and battlespace preparation for more damaging attacks. Karma Panda has earlier been active against Japan, South Korea, and the United States."

Knowing that spear phishing is one of their go-to social engineering tactics, stay safe out there and step those users through new-school security awareness training!

Topics: Phishing

Ready to Build a Security Culture That Lasts?

Stop treating training like a checkbox exercise. Using 15+ years of behavioral data, our AI-powered platform personalizes training for every user to significantly reduce human risk and stop attacks before they start.

Get a Quote

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the human and AI workforce to make safer security decisions every day. Trusted by over 70,000 organizations worldwide, we help strengthen security culture and manage risk. Our comprehensive AI-driven platform includes awareness and compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, agent security and more. As the only global security platform of its kind, KnowBe4 provides personalized content, tools, and techniques to keep the modern workforce safe from phishing, vishing, deepfakes, and emerging threats.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.