Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Chaos: a Stolen Backdoor Rising Again

released on 2018-02-15 @ 10:08:06 AM
This post describes a backdoor that spawns a fully encrypted and integrity checked reverse shell that was found in our SSH honeypot, and that was presented at GoSec 2017 in Montreal. We named the backdoor ‘Chaos’, following the name the attacker gave it on the system. After more research, we found out this backdoor was originally part of the ‘sebd’ rootkit that was active around 2013.