• Contact
  • Legal Pages
    • Privacy Policy
    • Terms of Use
    • DMCA
    • Cookie Privacy Policy
    • California Consumer Privacy Act (CCPA)
No Result
View All Result
Friday, December 5, 2025
The American News
ADVERTISEMENT
No Result
View All Result
The American News
No Result
View All Result

New Auto-Color Linux backdoor targets North American govts, universities

by theamericannews
February 26, 2025
in America
0
New Auto-Color Linux backdoor targets North American govts, universities
300
SHARES
1.9k
VIEWS
Share on FacebookShare on Twitter
ADVERTISEMENT

A previously undocumented Linux backdoor dubbed ‘Auto-Color’ was observed in attacks between November and December 2024, targeting universities and government organizations in North America and Asia.

According to Palo Alto Networks’ Unit 42 researchers who discovered the malware, it is highly evasive and difficult to remove from infected systems, capable of maintaining access for extended periods.

The malware features some similarities with the Symbiote Linux malware family, which was first documented by BlackBerry in 2022, but the two are distinct from each other.

Evasive Linux threat

Unit 42 does not have visibility into the initial infection vector, but the attack begins with the execution of a file disguised with benign names like”door”, “egg”, and “log.”

If the malware runs with root privileges, it installs a malicious library implant (libcext.so.2), disguised as the legitimate libcext.so.0 library, copies itself to a system directory (/var/log/cross/auto-color), and modifies ‘/etc/ld.preload’ to ensure the implant executes before any other system library.

If root access isn’t available, the malware still executes but skips the persistent mechanisms. Although this limits its long-term impact, it still provides remote access to threat actors who may be able to achieve root through other means.

Auto-Color infection chainAuto-Color infection chain
Source: Unit 42

Auto-Color decrypts command-and-control (C2) server information using a custom encryption algorithm and validates the exchange via a random 16-byte value handshake.

Custom encryption is used for obfuscation of C2 server addresses, configuration data, and network traffic, while the encryption key changes dynamically with each request to make detection more difficult.

Once the connection has been established, the C2 may order Auto-Color to perform one of the following actions:

Open a reverse shell, allowing the operators full remote access.
Execute arbitrary commands on the system.
Modify or create files to expand the infection.
Act as a proxy, forwarding attacker traffic.
Modify its configuration dynamically.

Commands supported by Auto-ColorCommands supported by Auto-Color
Source: Unit 42

Auto-Color also has rootkit-like features like hooking libc functions to intercept system calls, which it uses to hide C2 connections by modifying the /proc/net/tcp file.

Unit 42 says Auto-Color also features a built-in “kill switch,” which allows the attackers to immediately delete infection traces from the compromised machines to impede investigations.

How to defend

Given its stealth, modular design, and remote control features, Auto-Color is a serious threat to Linux systems, particularly those in government and academic environments targeted in the observed attacks.

Unit 42 suggests monitoring changes to ‘/etc/ld.preload,’ which is a key persistence mechanism, checking ‘/proc/net/tcp’ for output anomalies, and using behavior-based threat detection solutions.

The researchers have also listed indicators of compromise (IoCs) at the bottom of the report, so inspecting system logs and network traffic for connections to the listed C2 IPs is also crucial.

Source link : http://www.bing.com/news/apiclick.aspx?ref=FexRss&aid=&tid=67beb0e89d31487fb6568510c861c684&url=https%3A%2F%2Fwww.bleepingcomputer.com%2Fnews%2Fsecurity%2Fnew-auto-color-linux-backdoor-targets-north-american-govts-universities%2F&c=7655698239841125572&mkt=en-us

Author :

Publish date : 2025-02-25 03:51:00

Copyright for syndicated content belongs to the linked Source.

Tags: AmericaAmericanAutoColorbackdoorgovtsLinuxNorthTargetsUniversities
ADVERTISEMENT
Previous Post

What is the Five Eyes alliance that US wants Canada out of? Why is this a bad move? – Firstpost

Next Post

USA Tariffs: India And United States Of America In Talks To Reduce Tariffs On Certain American Goods

Next Post

USA Tariffs: India And United States Of America In Talks To Reduce Tariffs On Certain American Goods

Alabama’s Automakers Prepare for Trump’s Tariffs: A Bold New Strategy Unfolds!
Alabama

Alabama’s Automakers Prepare for Trump’s Tariffs: A Bold New Strategy Unfolds!

by Charlotte Adams
December 5, 2025
0

As the threat of new tariffs looms from the Trump administration, Alabama's automakers are rising to the occasion, showcasing their...

Read more
Heartbreaking Tragedy Exposes Critical Failures in America’s Pedestrian Safety

Heartbreaking Tragedy Exposes Critical Failures in America’s Pedestrian Safety

December 4, 2025
Uncover the Caribbean’s Best-Kept Secret: The Island Everyone is Talking About for Its Safety!

Uncover the Caribbean’s Best-Kept Secret: The Island Everyone is Talking About for Its Safety!

December 4, 2025
Antigua and Barbuda Poised to Shine as the Caribbean’s Second Fastest Growing Economy!

Antigua and Barbuda Poised to Shine as the Caribbean’s Second Fastest Growing Economy!

December 4, 2025
Exciting News: Aruba Reopens Its Borders to Latin America on December 1!

Exciting News: Aruba Reopens Its Borders to Latin America on December 1!

December 4, 2025
Urgent Warning: US Tariffs Could Jeopardize Bahamas’ Trade and Tourism!

Urgent Warning: US Tariffs Could Jeopardize Bahamas’ Trade and Tourism!

December 4, 2025
Barbados Welcomes a Tourism Boom as the US Overtakes the UK in Visitor Numbers for 2025!

Barbados Welcomes a Tourism Boom as the US Overtakes the UK in Visitor Numbers for 2025!

December 4, 2025
Peak Re Launches Thrilling New Venture in North America!

Peak Re Launches Thrilling New Venture in North America!

December 4, 2025
Bolivia’s Political Landscape Transforms: Centrist Candidate Surges as Voters Turn Away from Socialism

Bolivia’s Political Landscape Transforms: Centrist Candidate Surges as Voters Turn Away from Socialism

December 4, 2025

Bolsonaro’s Conviction: What It Means for U.S.-Brazil Relations

December 4, 2025

Categories

Archives

December 2025
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
293031  
« Nov    
  • Blog
  • California Consumer Privacy Act (CCPA)
  • Contact
  • Cookie Privacy Policy
  • DMCA
  • Privacy Policy
  • Terms of Use
  • The American News

© 2024

No Result
View All Result
  • Blog
  • California Consumer Privacy Act (CCPA)
  • Contact
  • Cookie Privacy Policy
  • DMCA
  • Privacy Policy
  • Terms of Use
  • The American News

© 2024

Go to mobile version

1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 * . *