CHALUBO

CHALUBOChalubo

Description

Since early September, SophosLabs has been monitoring an increasingly prolific attack targeting Internet-facing SSH servers on Linux-based systems that has been dropping a newly-discovered family of denial-of-service bots we’re calling Chalubo. The attackers encrypt both the main bot component and its corresponding Lua script using the ChaCha stream cipher. This adoption of anti-analysis techniques demonstrates an evolution in Linux malware, as the authors have adopted principles more common to Windows malware in an effort to thwart detection. Like some of its predecessors, Chalubo incorporates code from the Xor.DDoS and Mirai malware families.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
Chaos
Software
Atchbo
Software
Maze
Actor
Chaya_004
Software
cecilio
Software
Lalabitch_ransomware
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.