logo

New “CRON#TRAP” Campaign Exploits Emulated Linux Environments to Evade Detection

ID: 19b8aa6d-87f2-5e29-ba49-e4f323a5d201

STIX ID: report--19b8aa6d-87f2-5e29-ba49-e4f323a5d201

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2024-11-07

Date Updated: 2026-04-22

Author: do son

...
...

Securonix researchers uncovered the CRON#TRAP campaign in which attackers deliver a 285MB ZIP that launches a QEMU-emulated Tiny Core Linux environment (disguised as legitimate software) to run a preconfigured backdoor named "crondx". The emulated environment, with QEMU renamed to "fontdiag.exe", creates a persistent covert presence on the host, uses a customized Chisel tunnel with hard-coded C2 parameters for data exfiltration and remote commands, and contains artifacts (aliases, .ash_history entries, startup modifications, SSH keys) demonstrating attacker setup and persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.