Found 5 bookmarks
Custom sorting
Unveiling sedexp: A Stealthy Linux Malware Exploiting udev Rules
Unveiling sedexp: A Stealthy Linux Malware Exploiting udev Rules
Stroz Friedberg identified a stealthy malware, dubbed “sedexp,” utilizing Linux udev rules to achieve persistence and evade detection. This advanced threat, active since 2022, hides in plain sight while providing attackers with reverse shell capabilities and advanced concealment tactics.
·aon.com·
Unveiling sedexp: A Stealthy Linux Malware Exploiting udev Rules
Raspberry Robin’s Roshtyak: A Little Lesson in Trickery - Avast Threat Labs
Raspberry Robin’s Roshtyak: A Little Lesson in Trickery - Avast Threat Labs
We take a deep dive into Roshtyak, the DLL backdoor payload associated with Raspberry Robin. Roshtyak is full of anti-analysis tricks. Some are well-known, and some we have never seen before. From a technical perspective, the lengths Roshtyak takes to protect itself are extremely interesting. Roshtyak belongs to one of the best-protected malware strains we have ever seen. We hope by publishing our research and analysis of the malware and its protection tricks we will help fellow researchers recognize and respond to similar tricks, and harden their analysis environments, making them more resistant to the evasion techniques described.
·decoded.avast.io·
Raspberry Robin’s Roshtyak: A Little Lesson in Trickery - Avast Threat Labs