I love that basically no matter how skilled your attackers, they're still going to end up using cat unncessarily
Very nasty Linux backdoor with multiple components virustotal.com/gui/file/c69eβ¦
- Kills & uninstalls AV: clamav, avast, avg, drweb, esets
- Very persistent
- Uses Gates malware
- Uses Brootkit
- Uses CVE-2016-5195 to get root
- Infects other systems from known_hosts, .bash_history
8
29
1
145
Woke option: A version of cat which detects it was given no interesting options, only a single file argument, and its output is not a terminal; in that case, it kills its parent process.
Jun 27, 2019 Β· 6:34 AM UTC
1
10





