Malware

Detecting Melofee Stealth Backdoor Targeting Red Hat Linux

Linux Security
Rootkits
Malware
November 13, 2024

A new report from Qianxin's X Lab was released detailing new stealth malware targeting Red Hat 7.9 and similar systems: New Zero-Detection Variant of Melofee Backdoor from Winnti Strikes RHEL 7.9…

Rob Joyce Interview - Linux Critical Infrastructure Threats

Videos
Linux Security
Malware
Education
October 15, 2024

Watch as Rob Joyce, former head of the NSA Cybersecurity Directorate, discusses threats against Linux critical infrastructure with Sandfly founder Craig Rowland. This video will help security teams…

De-Cloaking Linux Stealth Malware and Rootkits: sedexp, Diamorphine, and Reptile

Linux Security
Videos
Rootkits
Malware
October 13, 2024

In this video we demonstrate Sandfly's new file and directory stealth rootkit de-cloaking feature on the sedexp malware targeting Linux. We also show how it works for the Diamorpine and Reptile…

Sandfly 5.2 - Linux Stealth Rootkit File and Directory De-Cloaking

Product Update
Linux Forensics
Rootkits
Malware
October 06, 2024

Sandfly 5.2 has a powerful new way to detect Linux stealth rootkits: Hidden file and directory de-cloaking. This feature will make files and directories hidden by many types of stealth rootkits…

Detecting Linux Stealth Rootkits with Directory Link Errors

Malware
Rootkits
Linux Forensics
June 25, 2024

Detecting stealth rootkits on Linux can be done from the command line. The secret is to ask the same question multiple ways to make sure all answers agree. If they don't all agree, something is…

XZ SSH Backdoor Detection Strategies

Malware
Rootkits
April 03, 2024

A sophisticated backdoor targeting the SSH service on Linux was made against the XZ compression library in a supply chain attack. The backdoor almost made it into most major Linux distributions until…