Discover this podcast and so much more

Podcasts are free to enjoy without a subscription. We also offer ebooks, audiobooks, and so much more for just $11.99/month.

SysJoker backdoor masquerades as benign updates. [Research Saturday]

SysJoker backdoor masquerades as benign updates. [Research Saturday]

FromCyberWire Daily


SysJoker backdoor masquerades as benign updates. [Research Saturday]

FromCyberWire Daily

ratings:
Length:
14 minutes
Released:
Feb 12, 2022
Format:
Podcast episode

Description

Guests Avigayil Mechtinger and Ryan Robinson from Intezer discuss SysJoker malware, a backdoor that targets Windows, Linux and MacOS, Malware targeting multiple operating systems has become no exception in the malware threat landscape. Vermilion Strike, which was documented just last September, is among the latest examples until now.  
In December 2021, the team at Intezer discovered a new multi-platform backdoor that targets Windows, Mac, and Linux. The Linux and Mac versions are fully undetected in VirusTotal. Intezer named this backdoor SysJoker.
SysJoker was first discovered during an active attack on a Linux-based web server of a leading educational institution. After further investigation, Intezer found that SysJoker also has Mach-O and Windows PE versions. Based on Command and Control (C2) domain registration and samples found in VirusTotal, Intezer estimates that the SysJoker attack was initiated during the second half of 2021.  
The research can be found here:
New SysJoker Backdoor Targets Windows, Linux, and macOS
Released:
Feb 12, 2022
Format:
Podcast episode