Cloud computing is making Linux a more tempting target for hackers

(Image credit: Pixabay)

Few people would take issue with saying Linux is more secure than Windows. However, Linux is not immune to malware. According to a new security report, hackers are paying more attention to it these days, just as more things shift to cloud computing.

The finding comes by way of Intezer Labs (via ZDNet), which highlighted in a security report an active botnet campaign affecting cloud servers running Linux.

"Linux threats are becoming more common. A contributing factor to this is the increasing shift and reliance on cloud environments, which are mostly based on Linux infrastructure. Hence, attackers have been adapting accordingly with new tools and techniques designed specifically for this infrastructure," Intezer Labs notes.

The interesting observation comes on the heels of a new malware strain dubbed Doki, which derives its name from targeting Docker servers in AWS, Azure, and other cloud platforms. According to the report, none of the 60 malware detection engines in VirusTotal have Doki on their radar since it was first analyzed on January 14, 2020.

That is both surprising and unsettling. VirusTotal is owned by a subsidiary of Google's parent company, Alphabet, and allows anyone to upload a file and have it scrutinized by dozens of virus engines to see if it is potentially malicious. It's a handy tool I have used on many occasions in the past, particularly when I used to conduct annual antivirus roundups for Maximum PC.

There could be other threats like Doki in the wild. And if not, there likely will be in the near future.

"A technique that has become popular is the abuse of misconfigured Docker API ports, where attackers scan for publicly accessible Docker servers and exploit them in order to set up their own containers and execute malware on the victim’s infrastructure," the report states.

Cut the cord...

(Image credit: Steelseries)

Best wireless gaming mouse: ideal cable-free rodents
Best wireless gaming keyboard: no wires, no worries
Best wireless gaming headset: top untethered audio

Doki is essentially a backdoor trojan that infiltrates Linux servers to steal resources for cryptocurrency mining. However, Intezer Labs says the malware payload is different than a standard cryptocurrency miner deployed in this type of attack.

"Doki uses a previously undocumented method to contact its operator by abusing the Dogecoin cryptocurrency blockchain in a unique way in order to dynamically generate its C2 domain address. The malware has managed to stay under the radar for over six months despite samples being publicly available in VirusTotal," the report adds.

Fortunately, this looks like it will be more of an annoyance for enterprise environments rather than nuisance for home users. Or in other words, if you've been thinking about switching a gaming PC to Linux, don't let this stop you.

Paul Lilly

Paul has been playing PC games and raking his knuckles on computer hardware since the Commodore 64. He does not have any tattoos, but thinks it would be cool to get one that reads LOAD"*",8,1. In his off time, he rides motorcycles and wrestles alligators (only one of those is true).

Latest in Linux
Valve Steam Deck OLED handheld PC
Valve continues to improve the gaming performance of Linux open source drivers for AMD GPUs, as part of the Mesa project
Asahi Linux on a mac book.
Developers finally get Linux running on an Apple M1-powered Mac
Three companies making DLSS possible on Linux OS
Nvidia DLSS is coming to boost frame rates for Linux gamers this month
https://pixabay.com/photos/linux-laptop-screen-wallpaper-wood-1962898/
Research scandal sees Linux Kernel ban 'all future contributions' from University of Minnesota
Cloud computing is making Linux a more tempting target for hackers
Watch this 90-year-old tech turned Linux terminal create ASCII art
Latest in News
A screenshot from SaGa Frontier 2, showing one of the protagonists wandering through a quaint fantasy village
One of Square Enix' most underrated PlayStation-era JRPGs just shadow dropped on Steam
The titular character from Princess Mononoke is depicted riding the wolf goddess Moro and carrying a spear.
Studio Ghibli AI image trend floods social media, cheered on by OpenAI and denounced by critics as an insult to Hayao Miyazaki
Marvel Rivals tier list - Wolverine
Marvel Rivals director says a future patch will reduce the shooter's insatiable hunger for RAM: 'It's a very big problem'
Hogwarts Legacy potions professor holding a potion
An unannounced Hogwarts Legacy expansion and 'definitive edition' have reportedly been cancelled
Story of Seasons - A cahacter in a purple tuxedo stands outside in a town square talking to the player
Story of Seasons is doing another Harvest Moon remake and it might be the best the series has ever looked
Assassin's Creed Shadows change seasons - An upper-body shot of Yasuke looking cheerfully up into the distance.
Assassin's Creed Shadows puts up the 'second highest day-one sales revenue in Assassin's Creed franchise history'