• Contact
  • Legal Pages
    • Privacy Policy
    • Terms of Use
    • DMCA
    • Cookie Privacy Policy
    • California Consumer Privacy Act (CCPA)
No Result
View All Result
Friday, December 12, 2025
The American News
ADVERTISEMENT
No Result
View All Result
The American News
No Result
View All Result

New Auto-Color Linux backdoor targets North American govts, universities

by theamericannews
February 26, 2025
in America
0
New Auto-Color Linux backdoor targets North American govts, universities
300
SHARES
1.9k
VIEWS
Share on FacebookShare on Twitter
ADVERTISEMENT

A previously undocumented Linux backdoor dubbed ‘Auto-Color’ was observed in attacks between November and December 2024, targeting universities and government organizations in North America and Asia.

According to Palo Alto Networks’ Unit 42 researchers who discovered the malware, it is highly evasive and difficult to remove from infected systems, capable of maintaining access for extended periods.

The malware features some similarities with the Symbiote Linux malware family, which was first documented by BlackBerry in 2022, but the two are distinct from each other.

Evasive Linux threat

Unit 42 does not have visibility into the initial infection vector, but the attack begins with the execution of a file disguised with benign names like”door”, “egg”, and “log.”

If the malware runs with root privileges, it installs a malicious library implant (libcext.so.2), disguised as the legitimate libcext.so.0 library, copies itself to a system directory (/var/log/cross/auto-color), and modifies ‘/etc/ld.preload’ to ensure the implant executes before any other system library.

If root access isn’t available, the malware still executes but skips the persistent mechanisms. Although this limits its long-term impact, it still provides remote access to threat actors who may be able to achieve root through other means.

Auto-Color infection chainAuto-Color infection chain
Source: Unit 42

Auto-Color decrypts command-and-control (C2) server information using a custom encryption algorithm and validates the exchange via a random 16-byte value handshake.

Custom encryption is used for obfuscation of C2 server addresses, configuration data, and network traffic, while the encryption key changes dynamically with each request to make detection more difficult.

Once the connection has been established, the C2 may order Auto-Color to perform one of the following actions:

Open a reverse shell, allowing the operators full remote access.
Execute arbitrary commands on the system.
Modify or create files to expand the infection.
Act as a proxy, forwarding attacker traffic.
Modify its configuration dynamically.

Commands supported by Auto-ColorCommands supported by Auto-Color
Source: Unit 42

Auto-Color also has rootkit-like features like hooking libc functions to intercept system calls, which it uses to hide C2 connections by modifying the /proc/net/tcp file.

Unit 42 says Auto-Color also features a built-in “kill switch,” which allows the attackers to immediately delete infection traces from the compromised machines to impede investigations.

How to defend

Given its stealth, modular design, and remote control features, Auto-Color is a serious threat to Linux systems, particularly those in government and academic environments targeted in the observed attacks.

Unit 42 suggests monitoring changes to ‘/etc/ld.preload,’ which is a key persistence mechanism, checking ‘/proc/net/tcp’ for output anomalies, and using behavior-based threat detection solutions.

The researchers have also listed indicators of compromise (IoCs) at the bottom of the report, so inspecting system logs and network traffic for connections to the listed C2 IPs is also crucial.

Source link : http://www.bing.com/news/apiclick.aspx?ref=FexRss&aid=&tid=67beb0e89d31487fb6568510c861c684&url=https%3A%2F%2Fwww.bleepingcomputer.com%2Fnews%2Fsecurity%2Fnew-auto-color-linux-backdoor-targets-north-american-govts-universities%2F&c=7655698239841125572&mkt=en-us

Author :

Publish date : 2025-02-25 03:51:00

Copyright for syndicated content belongs to the linked Source.

Tags: AmericaAmericanAutoColorbackdoorgovtsLinuxNorthTargetsUniversities
ADVERTISEMENT
Previous Post

What is the Five Eyes alliance that US wants Canada out of? Why is this a bad move? – Firstpost

Next Post

USA Tariffs: India And United States Of America In Talks To Reduce Tariffs On Certain American Goods

Next Post

USA Tariffs: India And United States Of America In Talks To Reduce Tariffs On Certain American Goods

Honoring a Legacy: Celebrating the Life and Impact of Jimmy Carter
US Virgin Islands

Honoring a Legacy: Celebrating the Life and Impact of Jimmy Carter

by Isabella Rossi
December 12, 2025
0

President Joe Biden expressed his deep sorrow over the passing of former President Jimmy Carter, honoring him as a "remarkable...

Read more
Venezuela’s Dilemma: How a Rightward Shift in Latin America Could Bolster U.S. National Security

Venezuela’s Dilemma: How a Rightward Shift in Latin America Could Bolster U.S. National Security

December 12, 2025
Mark Sears: A Rising Star Earns AP All-American First Team Honors!

Mark Sears: A Rising Star Earns AP All-American First Team Honors!

December 12, 2025
Rural America Revealed: Challenging Myths About Population Decline and the 2024 Election Landscape

Rural America Revealed: Challenging Myths About Population Decline and the 2024 Election Landscape

December 12, 2025
Discover the Magic of Queen Elizabeth’s Enchanting Visit to Anguilla!

Discover the Magic of Queen Elizabeth’s Enchanting Visit to Anguilla!

December 12, 2025
Discover the Thriving Spirit of Antigua and Barbuda with the Exciting ‘Be Here’ Bus Campaign!

Discover the Thriving Spirit of Antigua and Barbuda with the Exciting ‘Be Here’ Bus Campaign!

December 12, 2025
Discover Your Dream Caribbean Escapes for an Unforgettable 2025 Vacation: From France to Jamaica and Beyond!

Discover Your Dream Caribbean Escapes for an Unforgettable 2025 Vacation: From France to Jamaica and Beyond!

December 12, 2025
Devastating Day at Sea: Two Passengers Lose Their Lives in Separate Drowning Incidents on Carnival Cruise

Devastating Day at Sea: Two Passengers Lose Their Lives in Separate Drowning Incidents on Carnival Cruise

December 12, 2025
Travel Troubles Ahead: Barbados and Caribbean Nations Face Visa Delays and Travel Bans to the US in 2025!

Travel Troubles Ahead: Barbados and Caribbean Nations Face Visa Delays and Travel Bans to the US in 2025!

December 12, 2025

Unveiling the Unsung Heroes: How Bermuda Reinsurers Shape the U.S. Health Market

December 12, 2025

Categories

Archives

December 2025
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
293031  
« Nov    
  • Blog
  • California Consumer Privacy Act (CCPA)
  • Contact
  • Cookie Privacy Policy
  • DMCA
  • Privacy Policy
  • Terms of Use
  • The American News

© 2024

No Result
View All Result
  • Blog
  • California Consumer Privacy Act (CCPA)
  • Contact
  • Cookie Privacy Policy
  • DMCA
  • Privacy Policy
  • Terms of Use
  • The American News

© 2024

Go to mobile version

1 - 2 - 3 - 4 - 5 - 6 - 7 - 8 * . *