New “CRON#TRAP” Campaign Exploits Emulated Linux Environments to Evade Detection
ID: 19b8aa6d-87f2-5e29-ba49-e4f323a5d201
STIX ID: report--19b8aa6d-87f2-5e29-ba49-e4f323a5d201
Feed Name: securityonline.info
Securonix researchers uncovered the CRON#TRAP campaign in which attackers deliver a 285MB ZIP that launches a QEMU-emulated Tiny Core Linux environment (disguised as legitimate software) to run a preconfigured backdoor named "crondx". The emulated environment, with QEMU renamed to "fontdiag.exe", creates a persistent covert presence on the host, uses a customized Chisel tunnel with hard-coded C2 parameters for data exfiltration and remote commands, and contains artifacts (aliases, .ash_history entries, startup modifications, SSH keys) demonstrating attacker setup and persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
