Researchers studying cybersecurity have revealed a new attack chain that uses phishing emails to spread the open-source backdoor VShell.
According to a technical article by Trellix researcher Sagar Bade, the malware attack chain that is unique to Linux begins with a spam email that contains a malicious RAR archive file.
The payload is encoded in the filename itself; it is not concealed within the file content or a macro. The attacker transforms a straightforward file listing process into an automatic malware execution trigger by deftly utilizing shell command injection and Base64-encoded Bash payloads.
The cybersecurity firm added that the method exploits a straightforward but risky pattern frequently seen in shell scripts that occurs when file names are evaluated with insufficient sanitization allowing a simple command like eval read more about Linux Malware Delivered via Malicious RAR Filenames Evades Antivirus Detection.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
