{"id":2904,"date":"2021-05-31T22:10:49","date_gmt":"2021-06-01T03:10:49","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2904"},"modified":"2021-05-31T22:10:50","modified_gmt":"2021-06-01T03:10:50","slug":"facefish-a-new-threat-targeting-linux","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/facefish-a-new-threat-targeting-linux\/","title":{"rendered":"Facefish &#8211; A new threat targeting Linux"},"content":{"rendered":"\n<p>Cybersecurity experts at Qihoo 360 NETLAB published details about a new backdoor, called Facefish, that threat actors can use to steal login credentials and execute arbitrary commands on Linux systems. Researchers based on their ability to distribute different &#8216;rootkits&#8217; and use Blowfish encryption to encrypt communications with the C2.<\/p>\n\n\n\n<p>Facefish consists of two parts, the &#8216;dropper&#8217; and the &#8216;rootkit&#8217;. The latter works in user space (Ring 3), and is activated by preloading libraries (LD_PRELOAD). Once in operation, it monitors calls to functions of the ssh \/ sshd programs, capturing their credentials. For its part, the &#8216;dropper&#8217; is in charge of decrypting the configuration and configuring the &#8216;rootkit&#8217;, storing it in the directory (\/lib64\/libs.so) and adjusting the file (\/etc\/ld.so.preload), which it will force its load every time any program is run.<\/p>\n\n\n\n<p>Rootkits are especially dangerous as they allow attackers to gain elevated privileges by interfering with the operation of sensitive applications. Additionally, the ability to disguise themselves as part of the operating system provides them with a high degree of stealth and evasion.<\/p>\n\n\n\n<p>The exact vulnerability exploited by the threat actors has yet to be determined, but experts noted that CWP has been affected by multiple flaws. Facefish specifically targets Linux x64 systems and can remove multiple rootkits at different times, it uses the Blowfish encryption algorithm for C2 communications.<\/p>\n\n\n\n<p><strong><em>The malware supports multiple functions, including:<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong>Upload device information<\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong>Steal user credentials<\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong>Bounce Shell<\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong>Execute arbitrary commands<\/p>\n\n\n\n<p>In addition, Facefish also employs a complex communication protocol and encryption algorithm, using instructions starting with 0x2XX to exchange public keys and BlowFish to encrypt communication data with the C2 server. <\/p>\n\n\n\n<p><strong><em>Some of the C2 commands sent by the server are as follows:<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong>0x300 &#8211; Report stolen credential information<\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong>0x301 &#8211; Collect details of the &#8220;uname&#8221; command<\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong>0x302 &#8211; Run reverse shell<\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong>0x310 &#8211; Execute any system command<\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong>0x311 &#8211; Sends the result of the bash execution <\/p>\n\n\n\n<p><strong><em>\u25b8<\/em><\/strong>0x312 &#8211; Host Information Report<\/p>\n\n\n\n<p>Related reads:<br><a href=\"https:\/\/truxgoservers.com\/blog\/drovorub-a-malware-based-on-linux-system\/\">Drovorub \u2013 A Malware based on Linux system<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/discreet-linux-a-distro-for-security-against-trojans\/\">Discreet Linux \u2013 A distro for security against Trojans<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity experts at Qihoo 360 NETLAB published details about a new backdoor, called Facefish, that threat actors can use to steal login credentials and execute arbitrary commands on Linux systems. Researchers based on their ability to distribute different &#8216;rootkits&#8217; and use Blowfish encryption to encrypt communications with the C2. Facefish consists of two parts, the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2905,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-2904","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Facefish - A new threat targeting Linux - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"A new backdoor threat capable of stealing the login credentials has appeared which is known as Facefish and today we will see it.....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/facefish-a-new-threat-targeting-linux\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Facefish - A new threat targeting Linux - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"A new backdoor threat capable of stealing the login credentials has appeared which is known as Facefish and today we will see it.....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/facefish-a-new-threat-targeting-linux\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-06-01T03:10:49+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-06-01T03:10:50+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Facefish.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1366\" \/>\n\t<meta property=\"og:image:height\" content=\"768\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/facefish-a-new-threat-targeting-linux\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/facefish-a-new-threat-targeting-linux\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Facefish &#8211; A new threat targeting Linux\",\"datePublished\":\"2021-06-01T03:10:49+00:00\",\"dateModified\":\"2021-06-01T03:10:50+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/facefish-a-new-threat-targeting-linux\\\/\"},\"wordCount\":346,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/facefish-a-new-threat-targeting-linux\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Facefish.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/facefish-a-new-threat-targeting-linux\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/facefish-a-new-threat-targeting-linux\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/facefish-a-new-threat-targeting-linux\\\/\",\"name\":\"Facefish - A new threat targeting Linux - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/facefish-a-new-threat-targeting-linux\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/facefish-a-new-threat-targeting-linux\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Facefish.jpg\",\"datePublished\":\"2021-06-01T03:10:49+00:00\",\"dateModified\":\"2021-06-01T03:10:50+00:00\",\"description\":\"A new backdoor threat capable of stealing the login credentials has appeared which is known as Facefish and today we will see it.....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/facefish-a-new-threat-targeting-linux\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/facefish-a-new-threat-targeting-linux\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/facefish-a-new-threat-targeting-linux\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Facefish.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Facefish.jpg\",\"width\":1366,\"height\":768},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/facefish-a-new-threat-targeting-linux\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Facefish &#8211; A new threat targeting Linux\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Facefish - A new threat targeting Linux - Truxgo Server Blog","description":"A new backdoor threat capable of stealing the login credentials has appeared which is known as Facefish and today we will see it.....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/facefish-a-new-threat-targeting-linux\/","og_locale":"es_MX","og_type":"article","og_title":"Facefish - A new threat targeting Linux - Truxgo Server Blog","og_description":"A new backdoor threat capable of stealing the login credentials has appeared which is known as Facefish and today we will see it.....","og_url":"https:\/\/truxgoservers.com\/blog\/facefish-a-new-threat-targeting-linux\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-06-01T03:10:49+00:00","article_modified_time":"2021-06-01T03:10:50+00:00","og_image":[{"width":1366,"height":768,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Facefish.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/facefish-a-new-threat-targeting-linux\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/facefish-a-new-threat-targeting-linux\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Facefish &#8211; A new threat targeting Linux","datePublished":"2021-06-01T03:10:49+00:00","dateModified":"2021-06-01T03:10:50+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/facefish-a-new-threat-targeting-linux\/"},"wordCount":346,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/facefish-a-new-threat-targeting-linux\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Facefish.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/facefish-a-new-threat-targeting-linux\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/facefish-a-new-threat-targeting-linux\/","url":"https:\/\/truxgoservers.com\/blog\/facefish-a-new-threat-targeting-linux\/","name":"Facefish - A new threat targeting Linux - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/facefish-a-new-threat-targeting-linux\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/facefish-a-new-threat-targeting-linux\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Facefish.jpg","datePublished":"2021-06-01T03:10:49+00:00","dateModified":"2021-06-01T03:10:50+00:00","description":"A new backdoor threat capable of stealing the login credentials has appeared which is known as Facefish and today we will see it.....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/facefish-a-new-threat-targeting-linux\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/facefish-a-new-threat-targeting-linux\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/facefish-a-new-threat-targeting-linux\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Facefish.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Facefish.jpg","width":1366,"height":768},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/facefish-a-new-threat-targeting-linux\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Facefish &#8211; A new threat targeting Linux"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2904","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2904"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2904\/revisions"}],"predecessor-version":[{"id":2923,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2904\/revisions\/2923"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2905"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2904"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2904"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2904"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}