timb-machine / linux-malware

Tracking interesting Linux (and UNIX) malware. Send PRs
The Unlicense
1.1k stars 91 forks source link

[Intel]: https://www.group-ib.com/blog/krasue-rat/ #797

Open timb-machine opened 6 months ago

timb-machine commented 6 months ago

Area

Malware reports

Parent threat

Persistence, Privilege Escalation, Defense Evasion, Command and Control

Finding

https://www.group-ib.com/blog/krasue-rat/

Industry reference

uses:AbnormalSignal attack:T1071:Application Layer Protocol uses:RTSP attack:T1547.006:Kernel Modules and Extensions attack:T1564.001:Hidden Files and Directories attack:T1205:Traffic Signaling

Malware reference

Krasue Diamorphine https://github.com/timb-machine/linux-malware/issues/217 Suterusu https://github.com/timb-machine/linux-malware/issues/491 Rooty https://github.com/timb-machine/linux-malware/issues/440

Actor reference

No response

Component

Linux

Scenario

No response