EXECUTIVE SUMMARY
A new Linux variant of DinodasRAT also known as XDealer has emerged demonstrating a concerning expansion of its capabilities beyond Windows environments. This multi-platform backdoor, coded in C++, poses a significant threat to Linux-based systems. Notably, this variant, labeled as V10 by the attackers, exhibits sophisticated functionalities aimed at surveillance and data harvesting. Researcher has Identified on Operation Jacana targeting government entities in Guyana, this Linux variant underscores the evolving landscape of cyber threats.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A new Linux variant of DinodasRAT also known as XDealer has emerged demonstrating a concerning expansion of its capabilities beyond Windows environments. This multi-platform backdoor, coded in C++, poses a significant threat to Linux-based systems. Notably, this variant, labeled as V10 by the attackers, exhibits sophisticated functionalities aimed at surveillance and data harvesting. Researcher has Identified on Operation Jacana targeting government entities in Guyana, this Linux variant underscores the evolving landscape of cyber threats.[emaillocker id="1283"]
The DinodasRAT Linux implant demonstrates a multi-layered approach to compromise and maintain control over targeted systems. Upon execution, it establishes persistence through SystemV or SystemD startup scripts, tailoring its approach based on the detected Linux distribution. To generate a unique identifier for each victim, it combines the date of infection, system hardware information, a random number, and the backdoor version. Communication with the command-and-control (C2) server is facilitated over TCP or UDP, with hard-coded server addresses and a range of commands for data manipulation and system control. Encryption techniques using the Tiny Encryption Algorithm (TEA) in CBC mode secure communication channels between the implant and the C2 server, ensuring covert operations.
The emergence of the DinodasRAT Linux variant underscores the expanding threat landscape faced by Linux-based systems. With its ability to establish persistence, gather system information, and communicate with remote servers, this backdoor presents a significant risk of unauthorized access and data exfiltration. The observed targeting of various countries further emphasizes the global impact of this threat. As such, heightened vigilance and robust cybersecurity measures are imperative to mitigate the risks posed by DinodasRAT and similar advanced persistent threats.
THREAT PROFILE:

REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/03/linux-version-of-dinodasrat-spotted-in.html