Threat Advisory

KATARU IoT Malware Exploits Linux Local Privilege Escalation Flaws

Threat: Vulnerability
Threat Actor Name: Watchdog
Targeted Region: Vietnam
Alias: Thief Libra
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

These vulnerabilities pose a significant risk as they allow for local privilege escalation, potentially leading to unauthorized access and control of affected systems. Affected version ranges are not explicitly stated in the article. (CVSS 9.8 — Critical): The vulnerability allows unprivileged users to gain root access on affected Linux systems by exploiting a misconfiguration where is writable by the current user.

(CVSS 7.2 — High): This vulnerability also enables unprivileged users to gain root access on affected Linux systems, although it appears to be copied from public code with little or no modification. (CVSS 5.9 — Medium): The sample attempts to exploit this vulnerability as a last resort, but the code seems to have been copied directly from public sources without proper testing or porting across architectures.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

These vulnerabilities pose a significant risk as they allow for local privilege escalation, potentially leading to unauthorized access and control of affected systems. Affected version ranges are not explicitly stated in the article. (CVSS 9.8 — Critical): The vulnerability allows unprivileged users to gain root access on affected Linux systems by exploiting a misconfiguration where is writable by the current user.

(CVSS 7.2 — High): This vulnerability also enables unprivileged users to gain root access on affected Linux systems, although it appears to be copied from public code with little or no modification. (CVSS 5.9 — Medium): The sample attempts to exploit this vulnerability as a last resort, but the code seems to have been copied directly from public sources without proper testing or porting across architectures.[emaillocker id="1283"]

These vulnerabilities collectively present a significant risk to Linux systems that are not properly configured or maintained.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1190 Exploit Public Facing Application-
Execution T1059.003 Command and Scripting Interpreter Windows Command Shell
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Privileged Escalation T1068 Exploitation for Privilege Escalation -
Defence Evasion T1027.002 Obfuscated Files or Information Software Packing
Command and control T1071.001 Application Layer Protocol Web Protocols
Command and control T1573.001 Encrypted Channel Symmetric Cryptography
Exfiltration T1041 Exfiltration Over C2 Channel -

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu