Curse of the Krasue: New Linux Remote Access Trojan targets Thailand
ID: 7f81053a-d232-5974-9f4f-c4281a6018b3
STIX ID: report--7f81053a-d232-5974-9f4f-c4281a6018b3
Feed Name: Group-IB Blog
Group-IB describes Krasue, a stealthy Linux Remote Access Trojan active since 2021 and observed primarily against Thai telecommunications firms; Krasue includes embedded Linux kernel module rootkits (multiple compiled versions for different kernels), a UDP-based C2 with AES-CBC using a static key, uncommon RTSP "DESCRIBE" alive pings, hardcoded internal and external C2 addresses, and a set of YARA rules and file/rootkit hashes for detection. The report details the malware's persistence and evasion techniques, provides IOCs and mitigation recommendations (kernel module signing, log monitoring, trusted sources), and notes code overlaps with XorDdos but no definitive attribution or full understanding of initial access vectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
