• Contact
  • Legal Pages
    • Privacy Policy
    • Terms of Use
    • DMCA
    • Cookie Privacy Policy
    • California Consumer Privacy Act (CCPA)
No Result
View All Result
Sunday, December 21, 2025
The American News
ADVERTISEMENT
No Result
View All Result
The American News
No Result
View All Result

New Auto-Color Linux backdoor targets North American govts, universities

by theamericannews
February 26, 2025
in America
0
New Auto-Color Linux backdoor targets North American govts, universities
300
SHARES
1.9k
VIEWS
Share on FacebookShare on Twitter
ADVERTISEMENT

A previously undocumented Linux backdoor dubbed ‘Auto-Color’ was observed in attacks between November and December 2024, targeting universities and government organizations in North America and Asia.

According to Palo Alto Networks’ Unit 42 researchers who discovered the malware, it is highly evasive and difficult to remove from infected systems, capable of maintaining access for extended periods.

The malware features some similarities with the Symbiote Linux malware family, which was first documented by BlackBerry in 2022, but the two are distinct from each other.

Evasive Linux threat

Unit 42 does not have visibility into the initial infection vector, but the attack begins with the execution of a file disguised with benign names like”door”, “egg”, and “log.”

If the malware runs with root privileges, it installs a malicious library implant (libcext.so.2), disguised as the legitimate libcext.so.0 library, copies itself to a system directory (/var/log/cross/auto-color), and modifies ‘/etc/ld.preload’ to ensure the implant executes before any other system library.

If root access isn’t available, the malware still executes but skips the persistent mechanisms. Although this limits its long-term impact, it still provides remote access to threat actors who may be able to achieve root through other means.

Auto-Color infection chainAuto-Color infection chain
Source: Unit 42

Auto-Color decrypts command-and-control (C2) server information using a custom encryption algorithm and validates the exchange via a random 16-byte value handshake.

Custom encryption is used for obfuscation of C2 server addresses, configuration data, and network traffic, while the encryption key changes dynamically with each request to make detection more difficult.

Once the connection has been established, the C2 may order Auto-Color to perform one of the following actions:

Open a reverse shell, allowing the operators full remote access.
Execute arbitrary commands on the system.
Modify or create files to expand the infection.
Act as a proxy, forwarding attacker traffic.
Modify its configuration dynamically.

Commands supported by Auto-ColorCommands supported by Auto-Color
Source: Unit 42

Auto-Color also has rootkit-like features like hooking libc functions to intercept system calls, which it uses to hide C2 connections by modifying the /proc/net/tcp file.

Unit 42 says Auto-Color also features a built-in “kill switch,” which allows the attackers to immediately delete infection traces from the compromised machines to impede investigations.

How to defend

Given its stealth, modular design, and remote control features, Auto-Color is a serious threat to Linux systems, particularly those in government and academic environments targeted in the observed attacks.

Unit 42 suggests monitoring changes to ‘/etc/ld.preload,’ which is a key persistence mechanism, checking ‘/proc/net/tcp’ for output anomalies, and using behavior-based threat detection solutions.

The researchers have also listed indicators of compromise (IoCs) at the bottom of the report, so inspecting system logs and network traffic for connections to the listed C2 IPs is also crucial.

Source link : http://www.bing.com/news/apiclick.aspx?ref=FexRss&aid=&tid=67beb0e89d31487fb6568510c861c684&url=https%3A%2F%2Fwww.bleepingcomputer.com%2Fnews%2Fsecurity%2Fnew-auto-color-linux-backdoor-targets-north-american-govts-universities%2F&c=7655698239841125572&mkt=en-us

Author :

Publish date : 2025-02-25 03:51:00

Copyright for syndicated content belongs to the linked Source.

Tags: AmericaAmericanAutoColorbackdoorgovtsLinuxNorthTargetsUniversities
ADVERTISEMENT
Previous Post

What is the Five Eyes alliance that US wants Canada out of? Why is this a bad move? – Firstpost

Next Post

USA Tariffs: India And United States Of America In Talks To Reduce Tariffs On Certain American Goods

Next Post

USA Tariffs: India And United States Of America In Talks To Reduce Tariffs On Certain American Goods

Embark on an Unforgettable Adventure Aboard the MSC World America!
Canada

Embark on an Unforgettable Adventure Aboard the MSC World America!

by Victoria Jones
December 21, 2025
0

Step aboard the MSC World America with ELLE Canada Magazine and immerse yourself in a world of luxury and innovation!...

Read more
June Sees a Decline in Cayman Travelers Heading to the US Amid Global Economic Challenges

June Sees a Decline in Cayman Travelers Heading to the US Amid Global Economic Challenges

December 21, 2025
Journey from California to Colombia: Unveiling a Happier, Safer Life!

Journey from California to Colombia: Unveiling a Happier, Safer Life!

December 21, 2025
Skyward Turmoil: How Avianca Flight Disruptions Are Shaking Up Travel in Costa Rica and Central America

Skyward Turmoil: How Avianca Flight Disruptions Are Shaking Up Travel in Costa Rica and Central America

December 21, 2025
New Visa Restrictions Target Cubans Participating in Labor Export Program

New Visa Restrictions Target Cubans Participating in Labor Export Program

December 21, 2025
Dominican Republic Takes Bold Steps to Combat Drug Trafficking by Opening Restricted Areas to U.S

Dominican Republic Takes Bold Steps to Combat Drug Trafficking by Opening Restricted Areas to U.S

December 21, 2025
Major Drug Bust: US and Dominican Forces Join Forces to Uncover Massive Cocaine Haul!

Major Drug Bust: US and Dominican Forces Join Forces to Uncover Massive Cocaine Haul!

December 21, 2025
Exciting News: Saint Kitts and Nevis, Haiti Join the CAF Family as New Shareholders!

Exciting News: Saint Kitts and Nevis, Haiti Join the CAF Family as New Shareholders!

December 21, 2025
U.S. Northern Command Wraps Up Exciting Arctic Edge 2025 Exercise!

U.S. Northern Command Wraps Up Exciting Arctic Edge 2025 Exercise!

December 21, 2025
ASU Pioneers the Path to Achieving UN Sustainable Development Goals Nationwide

ASU Pioneers the Path to Achieving UN Sustainable Development Goals Nationwide

December 21, 2025

Categories

Archives

December 2025
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
293031  
« Nov    
  • Blog
  • California Consumer Privacy Act (CCPA)
  • Contact
  • Cookie Privacy Policy
  • DMCA
  • Privacy Policy
  • Terms of Use
  • The American News

© 2024

No Result
View All Result
  • Blog
  • California Consumer Privacy Act (CCPA)
  • Contact
  • Cookie Privacy Policy
  • DMCA
  • Privacy Policy
  • Terms of Use
  • The American News

© 2024

Go to mobile version

1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 * . *