Undetectable CrossRAT malware targets Windows, MacOS, and Linux systems

>CrossRAT is a cross-platform remote access Trojan that can target all four popular desktop operating systems, Windows, Solaris, Linux, and macOS, enabling remote attackers to manipulate the file system, take screenshots, run arbitrary executables, and gain persistence on the infected systems.

>Moreover, for Linux systems, the malware also attempts to query systemd files to determine its distribution, like Arch Linux, Centos, Debian, Kali Linux, Fedora, and Linux Mint, among many more.

>CrossRAT then implements OS specific persistence mechanisms to automatically (re)executes whenever the infected system is rebooted and register itself to the C&C server, allowing remote attackers to send command and exfiltrate data.

>Only 2 out of 58 antivirus products detect CrossRAT at the time of writing, which means that your AV would hardly protect you from this threat.

thehackernews.com/2018/01/crossrat-malware.html

Luckily I maintain a secure system so I have nothing to fear.

>determine its distribution, like Arch Linux
and i was hoping its only for ubuntu
now im scared

How do they know it exists if it's undetectable?

...

>all four popular desktop operating systems, Windows, Solaris, Linux, and macOS
>popular desktop operating system
>solaris
doubt [x]

>popular desktop operating system
>linux

>solaris
literally what ?

>operating systems
>lunux

OpenBSD doesn't have this problem.

So all I gotta do is not install Java and I'll be golden?
Perfect, I wasn't planning on it.

>According to researchers, Dark Caracal hackers do not rely on any "zero-day exploits" to distribute its malware; instead, it uses basic social engineering via posts on Facebook groups and WhatsApp messages, encouraging users to visit hackers-controlled fake websites and download malicious applications.
>written in Java
Literally nothing.

This
Most normies dont even have java runtime environment installed on their machines. The ones who do and still get infected deserved it

I can write a program like that in a day, and it works by you downloading it by your own will and running it by your own will...HA...i really got you there, aren't i sneaky...

>linux
t...thanks poettering for systemd.

I'm kind of embarrassed that i did exactly this a few weeks ago. I seriously reconsider copy an pasting anything now. And sudo is fucking banished from any system, fuck that timeout shit.

> undetectable
> uses facebook social engineering to get morons to run bios patching code

yeah seems legit. they probably run commonsense 2016, which is way out of date

They obviously mean for anti-viruses, you pedantic faggots.

you fell for the meltdown check script, didn't you?

>using GNU/Linux
>installing anything non-free
>not installing everything from verified repos

This is literally flatpak-user level of retardedness needed to install said malware.

Joke on you I don't have a desktop operating system

it's "undetectable" if a big ass portion of antiviral software can't detect it you dumb ass brainlets

In general nothing is "undetectable" you just need to shift awareness to it

Isn't IBM still prone to remote DOS hacking?

I'd just like to interject for a moment. What you're referring to as Linux, is in fact, GNU/Linux, or as I've recently taken to calling it, GNU plus Linux. Linux is not an operating system unto itself, but rather another free component of a fully functioning GNU system made useful by the GNU corelibs, shell utilities and vital system components comprising a full OS as defined by POSIX.

Many computer users run a modified version of the GNU system every day, without realizing it. Through a peculiar turn of events, the version of GNU which is widely used today is often called "Linux", and many of its users are not aware that it is basically the GNU system, developed by the GNU Project.

There really is a Linux, and these people are using it, but it is just a part of the system they use. Linux is the kernel: the program in the system that allocates the machine's resources to the other programs that you run. The kernel is an essential part of an operating system, but useless by itself; it can only function in the context of a complete operating system. Linux is normally used in combination with the GNU operating system: the whole system is basically GNU with Linux added, or GNU/Linux. All the so-called "Linux" distributions are really distributions of GNU/Linux.

>have a 100% java-free machine
literally nothing, indeed.

>Solaris
>Popular
Year of the OpenIndiana desktop???!!!

>According to researchers, Dark Caracal hackers do not rely on any "zero-day exploits" to distribute its malware; instead, it uses basic social engineering via posts on Facebook groups and WhatsApp messages, encouraging users to visit hackers-controlled fake websites and download malicious applications.
Oh wow, it's literally fucking nothing.

Reminder that "literally nothing" social engineering caught quite a few Sup Forums freetards not a couple of weeks ago.

?

"check if your CPU is vulnerable to meltdown" script.

>Facekike
>Poosapp
Literally only normies will fall for this shit

Once again BSD wins. Tell me why you still respect a hobo and an autistic german Sup Forums?

TempleOS is safe by design.

>Linux systems
FALSE!

I can't be the only one amused ms av is one of the two to detect it, can I?

>the malware also attempts to query systemd files to determine its distribution
Hm...

>SystemDicks at it again

Nice autistic screeching, faggot.

>viruses
>in 2018
AV was obsoleted in 2006.

>systemd
Ah, Slackware master race decision justified.

>Moreover, for Linux systems, the malware also attempts to query systemd files to determine its distribution, like Arch Linux, Centos, Debian, Kali Linux, Fedora, and Linux Mint, among many more.

HAHAHA, OH WOW

>using GNU/Linux
>installing anything non-free

So 99% of the people who use Lunix then?

>intentionally misquoting me
(You) probably did notice that I said this could be avoided by installing everything through trusted repositories, right?

Seems like a lot of antivirus detects them now. It's funny but if you look at the picture on the website, Microsoft's antivirus actually detects it. Isn't Essentials supposed to be mediocre?

>linux
>an operating system

Microsoft had gotten their shit together for awhile now, probably develop the shit themselfs to make them seem better.

>Once executed on the targeted system, the implant (hmar6.jar) first checks the operating system it's running on and then installs itself accordingly.
>hmar6.jar
>.jar
Nigger please

My Android desktop doesn't have this problem

Nobody cares richard

How do people get their computers infected with shit like this anyway? It's been years since I've stumbled on a run-of-the-mill virus, let alone one of those doomsday devices.

yeah, they have their own problems.

Which ones?

social media goyim BTFO

How do you get infected by this? Some js exploit or do you have to be retarded and do "sudo ./suspicious_executable"?

>you fell for the meltdown check script, didn't you?
Which one was that?

Is Solaris actually more popular than BSD?

>Luckily recent versions of macOS do not ship with Java," Patrick said.

JAVA BTFO

Can't play Candy crush.

Solaris still has a following in these machines, user.