November 19, 2019 By David Bisson 2 min read

Researchers discovered a new backdoor family called ACBackdoor that is targeting both Linux and Windows systems.

Intezer first found the Linux variant of ACBackdoor on a Romanian-hosted server. Its researchers didn’t uncover any information about the delivery vector used for this version of the backdoor. They had more success with the Windows variant of the malware, however. They discovered that those behind the multiplatform backdoor had enough funding to purchase the Fallout exploit kit and use it to distribute their Windows-based malware via several malvertising campaigns.

Additional analysis revealed that the backdoor was capable of arbitrarily executing shell commands and binaries along with establishing persistence and implementing updates. This deep dive into the malware also revealed that the Linux variant was more sophisticated than and likely written before the Windows version. Intezer explained that this finding could indicate that ACBackdoor’s developers are more comfortable with developing Linux-based malware instead of threats for Windows systems.

Other Recently Discovered Backdoors

ACBackdoor isn’t the only new backdoor that security researchers have recently uncovered. In October 2019, security researcher Patrick Wardle analyzed AppleJeus, a new macOS backdoor developed by the infamous Lazarus APT group.

That was just a few days before ESET revealed that the Winnti Group was using a new backdoor called PortReuse to target organizations in the Asian gaming industry. Less than a month later, Kaspersky Lab unveiled its discovery that the Platinum group had begun using the Titanium backdoor against targets in South and Southeast Asia.

How to Defend Against ACBackdoor

Without a known delivery vector, it’s difficult for security professionals to take steps that can meaningfully protect their organizations against the Linux variant of ACBackdoor. That being said, they can use thoughtful prioritization of known software vulnerabilities to block attacks involving exploit kits like Fallout, including those that distribute the Windows-based version of the backdoor.

Companies should also use security information and event management (SIEM) data to receive context about their vulnerabilities, information that they can then use to craft a remediation strategy.

More from

How prepared are you for your first Gen AI disruption?

5 min read - Generative artificial intelligence (Gen AI) and its use by businesses to enhance operations and profits are the focus of innovation in virtually every sector and industry. Gartner predicts that global spending on AI software will surge from $124 billion in 2022 to $297 billion by 2027. Businesses are upskilling their teams and hiring costly experts to implement new use cases, new ways to leverage data and new ways to use open-source tooling and resources. What they have failed to look…

Cybersecurity crisis communication: What to do

4 min read - Cybersecurity experts tell organizations that the question is not if they will become the target of a cyberattack but when. Often, the focus of response preparedness is on the technical aspects — how to stop the breach from continuing, recovering data and getting the business back online. While these tasks are critical, many organizations overlook a key part of response preparedness: crisis communication.Because a brand’s reputation often takes a significant hit, a cyberattack can significantly affect the company’s future success…

Brands are changing cybersecurity strategies due to AI threats

3 min read -  Over the past 18 months, AI has changed how we do many things in our work and professional lives — from helping us write emails to affecting how we approach cybersecurity. A recent Voice of SecOps 2024 study found that AI was a huge reason for many shifts in cybersecurity over the past 12 months. Interestingly, AI was both the cause of new issues as well as quickly becoming a common solution for those very same challenges.The study was conducted…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today