#qubitstrike — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #qubitstrike, aggregated by home.social.
-
I got to take apart a fantastic bit of #Linux #malware this week and have published the results: https://unfinished.bike/qubitstrike-and-diamorphine-linux-kernel-rootkits-go-mainstream - #QubitStrike has a bit of everything:
- Two #Linux #rootkits (kernel and user-mode)
- Process hiding
- Credential theft
- SSH backdoor
- A viral component
- A cryptocurrency miner
- Telegram integrationI had a lot of fun with this one. Now to convert these learnings into #detection rule updates!
-
I got to take apart a fantastic bit of #Linux #malware this week and have published the results: https://unfinished.bike/qubitstrike-and-diamorphine-linux-kernel-rootkits-go-mainstream - #QubitStrike has a bit of everything:
- Two #Linux #rootkits (kernel and user-mode)
- Process hiding
- Credential theft
- SSH backdoor
- A viral component
- A cryptocurrency miner
- Telegram integrationI had a lot of fun with this one. Now to convert these learnings into #detection rule updates!
-
@BenjaminHCCarr I just wrote an in-depth article on #QubitStrike - https://unfinished.bike/qubitstrike-and-diamorphine-linux-kernel-rootkits-go-mainstream
FWIW, the only thing Qubitstrike does via Telegram is broadcast its health & credentials at install time.
Hope you enjoy!
-
@BenjaminHCCarr I just wrote an in-depth article on #QubitStrike - https://unfinished.bike/qubitstrike-and-diamorphine-linux-kernel-rootkits-go-mainstream
FWIW, the only thing Qubitstrike does via Telegram is broadcast its health & credentials at install time.
Hope you enjoy!
-
Heads Up #HPC, #EDU, and #BioTech #SysAdmins!
#Qubitstrike #Malware Hits #Jupyter Notebooks for #Cryptojacking and Cloud Data
Qubitstrike Malware Uses Discord for C2 Communications in Cryptojacking Campaign Targeting #JupyterNotebooks https://www.hackread.com/qubitstrike-malware-jupyter-notebook-cryptojacking-cloud-data/ -
Heads Up #HPC, #EDU, and #BioTech #SysAdmins!
#Qubitstrike #Malware Hits #Jupyter Notebooks for #Cryptojacking and Cloud Data
Qubitstrike Malware Uses Discord for C2 Communications in Cryptojacking Campaign Targeting #JupyterNotebooks https://www.hackread.com/qubitstrike-malware-jupyter-notebook-cryptojacking-cloud-data/