{"id":3458,"date":"2021-08-09T15:14:25","date_gmt":"2021-08-09T20:14:25","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3458"},"modified":"2021-08-09T15:14:33","modified_gmt":"2021-08-09T20:14:33","slug":"wellmess-malware-that-attacks-linux-and-windows","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/wellmess-malware-that-attacks-linux-and-windows\/","title":{"rendered":"WellMess Malware that attacks Linux and Windows"},"content":{"rendered":"\n<p>Linux and Mac are definitely more secure operating system options than Microsoft Windows. But this does not mean that hackers cannot find ways to infect machines running these operating systems. Known as WellMess, this malware affects both Linux and Windows operating systems. In addition, it has two versions and although both versions of the malware remain the same, there are some minor differences. <\/p>\n\n\n\n<p>Like other malicious programs, WellMess communicates with your command and control (C&amp;C) center and downloads commands to perform other actions. Commands can be given from the C&amp;C server to upload \/ download files and execute arbitrary shell commands. The Windows version also has the ability to run PowerShell scripts. WellMess malware was first reported in mid-2018. And newer variants of the 2020 malware have also been found, which have a wide range of additional features from the original samples.<\/p>\n\n\n\n<p>The most recent WellNess samples differ from the 2018 samples as they now support communication with the C2 server via three separate communication methods: HTTP, HTTPS and DNS. For each communication method, the malware follows a similar process; establishes a connection with the C2 and then goes into an infinite loop to exchange data. The details of the initial connection differ for each method, but the main loop that exchanges data uses the same functions to perform malicious functions.<\/p>\n\n\n\n<p>Other reads:<br><a href=\"https:\/\/truxgoservers.com\/blog\/drovorub-a-malware-based-on-linux-system\/\">Drovorub \u2013 A Malware based on Linux system<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/\">Vovalex \u2013 Ransomware posing as Windows utilities<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Linux and Mac are definitely more secure operating system options than Microsoft Windows. But this does not mean that hackers cannot find ways to infect machines running these operating systems. Known as WellMess, this malware affects both Linux and Windows operating systems. In addition, it has two versions and although both versions of the malware [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3459,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36,35],"class_list":["post-3458","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-malware"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>WellMess Malware that attacks Linux and Windows - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Today, we will see a malware that attacks both Windows and Linux which is known as WellMess and we will see how it works......\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/wellmess-malware-that-attacks-linux-and-windows\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"WellMess Malware that attacks Linux and Windows - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Today, we will see a malware that attacks both Windows and Linux which is known as WellMess and we will see how it works......\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/wellmess-malware-that-attacks-linux-and-windows\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-08-09T20:14:25+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-08-09T20:14:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/WellMess.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"825\" \/>\n\t<meta property=\"og:image:height\" content=\"510\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wellmess-malware-that-attacks-linux-and-windows\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wellmess-malware-that-attacks-linux-and-windows\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"WellMess Malware that attacks Linux and Windows\",\"datePublished\":\"2021-08-09T20:14:25+00:00\",\"dateModified\":\"2021-08-09T20:14:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wellmess-malware-that-attacks-linux-and-windows\\\/\"},\"wordCount\":244,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wellmess-malware-that-attacks-linux-and-windows\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/WellMess.jpeg\",\"keywords\":[\"Cybersecurity\",\"Malware\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wellmess-malware-that-attacks-linux-and-windows\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wellmess-malware-that-attacks-linux-and-windows\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wellmess-malware-that-attacks-linux-and-windows\\\/\",\"name\":\"WellMess Malware that attacks Linux and Windows - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wellmess-malware-that-attacks-linux-and-windows\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wellmess-malware-that-attacks-linux-and-windows\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/WellMess.jpeg\",\"datePublished\":\"2021-08-09T20:14:25+00:00\",\"dateModified\":\"2021-08-09T20:14:33+00:00\",\"description\":\"Today, we will see a malware that attacks both Windows and Linux which is known as WellMess and we will see how it works......\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wellmess-malware-that-attacks-linux-and-windows\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wellmess-malware-that-attacks-linux-and-windows\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wellmess-malware-that-attacks-linux-and-windows\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/WellMess.jpeg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/WellMess.jpeg\",\"width\":825,\"height\":510,\"caption\":\"Detecting malware program concept - binary code and malware warning. 3d rendering\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wellmess-malware-that-attacks-linux-and-windows\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"WellMess Malware that attacks Linux and Windows\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"WellMess Malware that attacks Linux and Windows - Truxgo Server Blog","description":"Today, we will see a malware that attacks both Windows and Linux which is known as WellMess and we will see how it works......","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/wellmess-malware-that-attacks-linux-and-windows\/","og_locale":"es_MX","og_type":"article","og_title":"WellMess Malware that attacks Linux and Windows - Truxgo Server Blog","og_description":"Today, we will see a malware that attacks both Windows and Linux which is known as WellMess and we will see how it works......","og_url":"https:\/\/truxgoservers.com\/blog\/wellmess-malware-that-attacks-linux-and-windows\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-08-09T20:14:25+00:00","article_modified_time":"2021-08-09T20:14:33+00:00","og_image":[{"width":825,"height":510,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/WellMess.jpeg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/wellmess-malware-that-attacks-linux-and-windows\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/wellmess-malware-that-attacks-linux-and-windows\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"WellMess Malware that attacks Linux and Windows","datePublished":"2021-08-09T20:14:25+00:00","dateModified":"2021-08-09T20:14:33+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/wellmess-malware-that-attacks-linux-and-windows\/"},"wordCount":244,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/wellmess-malware-that-attacks-linux-and-windows\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/WellMess.jpeg","keywords":["Cybersecurity","Malware"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/wellmess-malware-that-attacks-linux-and-windows\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/wellmess-malware-that-attacks-linux-and-windows\/","url":"https:\/\/truxgoservers.com\/blog\/wellmess-malware-that-attacks-linux-and-windows\/","name":"WellMess Malware that attacks Linux and Windows - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/wellmess-malware-that-attacks-linux-and-windows\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/wellmess-malware-that-attacks-linux-and-windows\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/WellMess.jpeg","datePublished":"2021-08-09T20:14:25+00:00","dateModified":"2021-08-09T20:14:33+00:00","description":"Today, we will see a malware that attacks both Windows and Linux which is known as WellMess and we will see how it works......","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/wellmess-malware-that-attacks-linux-and-windows\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/wellmess-malware-that-attacks-linux-and-windows\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/wellmess-malware-that-attacks-linux-and-windows\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/WellMess.jpeg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/WellMess.jpeg","width":825,"height":510,"caption":"Detecting malware program concept - binary code and malware warning. 3d rendering"},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/wellmess-malware-that-attacks-linux-and-windows\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"WellMess Malware that attacks Linux and Windows"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3458","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3458"}],"version-history":[{"count":3,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3458\/revisions"}],"predecessor-version":[{"id":3509,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3458\/revisions\/3509"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3459"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3458"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3458"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3458"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}