4 ms·
I was under the impression that persistent, but SILENT access was China's goal. Dropping files in home and /tmp/ seems like the total opposite of that and any c
by stepupmakeup 2y ago
I was under the impression that persistent, but SILENT access was China's goal. Dropping files in home and /tmp/ seems like the total opposite of that and any competent sysadmin would detect these anomalies manually real quick with a simple "ls -a", even possibly by accident.
- NegativeK 2y agoChinese threat actors are not one homogeneous group. Just like every other country out there.
- jchmbrln 2y agoFrom the article: > The WolfsBane Hider rootkit hooks many basic standard C library functions such as open, stat, readdir, and access. While these hooked functions invoke the original ones, they filter out any results related to the WolfsBane malware. I took this to mean some things like a simple “ls -a” might now leave out those suspicious results.