"Rising Threat: Magnet Goblin Exploits 1-Day Vulnerabilities to Install Linux Malware"

1 min read
Source: Ars Technica
"Rising Threat: Magnet Goblin Exploits 1-Day Vulnerabilities to Install Linux Malware"
Photo: Ars Technica
TL;DR Summary

Researchers have discovered a previously unseen Linux variant of the NerbianRAT malware, which has been circulating for at least two years and is installed through the exploitation of recently patched vulnerabilities. The malware, attributed to the threat actor Magnet Goblin, is used to steal credentials and has been deployed through 1-day vulnerabilities in various software, including Ivanti Secure Connect, Magento, and Qlink Sense. Checkpoint Research also identified a smaller version of the malware, MiniNerbian, used for backdooring servers running the Magento ecommerce platform. The Linux version of NerbianRAT lacks protective measures and has been observed stealing VPN credentials and connecting to attacker-controlled IPs.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

2 min

vs 3 min read

Condensed

77%

455103 words

Want the full story? Read the original article

Read on Ars Technica