Summary: [/subscribe_to_unlock_form]
Summary: [emaillocker id="1283"]
A new type of malware targeted at Linux systems has been connected to an unidentified Chinese state-sponsored hacking group. Researchers discovered three samples of the previously known dangerous software known as Mélofée which was first discovered in early 2022. An open-source project-based kernel-mode rootkit is one of the artifacts that is targeted to be dropped. Since at least 2020 a state-sponsored actor known as Earth Berberoka has primarily targeted gaming websites in China with multi-platform malware like HelloBot and Pupy RAT. Trend Micro reports that the Reptile rootkit has been used to hide some copies of the Python-based Pupy RAT
It has been seen that the installer and an individual binary package are downloaded from a remote server by shell instructions that are used to distribute both the implant and the rootkit. The rootkit only has a few features, primarily installing a hook designed for self-replication. The rootkit and an active server implant module are both extracted by the installer after it receives the binary package as an argument. The capabilities of Mélofée which enable it to communicate with a remote server and obtain instructions that enable it to operate on files, create sockets, run a shell, and issue arbitrary commands, are identical to those of other backdoors. Another implant, AlienReverse, leverages open-source software like EarthWorm and socks proxy and has code in common with Mélofée.
The Mélofée implant family is yet another tool in the armoury of state-sponsored Chinese attackers, which constantly innovate and create new technologies. Mélofée's capabilities are simple, they could allow opponents to carry out covert operations. The fact that these implants were not commonly seen indicates that the attackers are probably only using them on high-value targets.
Threat Profile:
| Tactic | Technique Id | Technique |
| Reconnaissance | T1592 | Gather Victim Host Information |
| Resource Development | T1583 | Acquire Infrastructure |
| T1587 | Develop Capabilities | |
| T1588 | Obtain Capabilities | |
| T1608 | Stage Capabilities | |
| Execution | T1059 | Command and Scripting Interpreter |
| Persistence | T1037 | Boot or Logon Initialization Scripts |
| Defense Evasion | T1564 | Hide Artifacts |
| T1562 | Impair Defenses | |
| T1070 | Indicator Removal | |
| T1599 | Network Boundary Bridging | |
| T1027 | Obfuscated Files or Information | |
| T1014 | Rootkit | |
| T1497 | Virtualization/Sandbox Evasion | |
| Discovery | T1083 | File and Directory Discovery |
| T1057 | Process Discovery | |
| T1082 | System Information Discovery | |
| Command and Control | T1071 | Application Layer Protocol |
| T1132 | Data Encoding | |
| T1573 | Encrypted Channel | |
| T1095 | Non-Application Layer Protocol | |
| T1571 | Non-Standard Port | |
| T1572 | Protocol Tunneling | |
| T1090 | Proxy |
References:
The following reports contain further technical details:
https://thehackernews.com/2023/03/melofee-researchers-uncover-new-linux.html
[/emaillocker]