The Evolution of Linux Binaries in Targeted Cloud Operations
ID: 59d0338d-2c1c-5a01-954d-de41313f4cff
STIX ID: report--59d0338d-2c1c-5a01-954d-de41313f4cff
Feed Name: Palo Alto Networks Unit 42
Unit 42 warns of a growing threat from ELF Linux binaries tailored to cloud environments, profiling five actively developed malware families (NoodleRAT, Winnti, SSHdInjector, Pygmy Goat, AcidRain/AcidPour) that enable persistence, C2, credential theft, exfiltration and destructive wiping; the report documents recent sightings and code updates, highlights techniques such as LD_PRELOAD and SSH daemon injection, and recommends deploying machine-learning cloud endpoint protections and proactive threat hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
