timb-machine / linux-malware

Tracking interesting Linux (and UNIX) malware. Send PRs
The Unlicense
1.13k stars 90 forks source link

[Intel]: https://www.welivesecurity.com/2023/04/20/linux-malware-strengthens-links-lazarus-3cx-supply-chain-attack/ #655

Open timb-machine opened 1 year ago

timb-machine commented 1 year ago

Area

Malware reports

Parent threat

Initial Access, Persistence, Privilege Escalation

Finding

https://www.welivesecurity.com/2023/04/20/linux-malware-strengthens-links-lazarus-3cx-supply-chain-attack/

Industry reference

attack:T1566.001:Spearphishing Attachment attack:T1546.004:Unix Shell Configuration Modification uses:RedirectionToNull uses:Go

Malware reference

wltm OdicLoader SimplexTea

Actor reference

Lazarus

Component

Linux

Scenario

No response