Researchers of ESET, a global leader in the cybersecurity market, have discovered Kobalos, a malware that attacks supercomputers.
I high performance computer (HPC) cluster. ESET worked together with CERN's cybersecurity team and other organizations to prevent attacks on scientific research networks. The victims included a major Asian Internet service provider (ISP), a North American endpoint security vendor and several private servers.
ESET researchers have reverse engineered this small but complex malware that can transfer to many operating systems, including Linux, BSD, Solaris and possibly even AIX and Windows. “We called this malware Kobalos due to the tiny size of the code and its insidiousness; in Greek mythology, a Kobalos is a mischievous little creature,” explained Marc-Etienne Léveillé, an ESET researcher who participated in the investigation. “It must be said that this level of sophistication is very rarely seen in Linux malware.
Kobalos is a backdoor containing a series of commands that do not reveal the attackers' intent. “Essentially, Kobalos allows remote access to the file system, and gives the possibility to generate terminal sessions and connect via proxy to other servers infected by this malware,” continued Léveillé.
Any server compromised by Kobalos can be transformed into a Command&Control (C&C) server by the hackers controlling it, through a single command. Since C&C server IP addresses and ports have fixed encodings in the executables, operators can generate new Kobalos specimens that take advantage of this new C&C server. Furthermore, on most systems compromised by Kobalos, the SecureShell (SSH) client is no longer able to protect credentials.
"Anyone using an SSH server on an infected computer will have their credentials stolen. These can later be used by attackers to install Kobalos on the newly hacked server," Léveillé added. Setting up two-factor authentication for connecting to SSH servers can mitigate the threat, as the use of stolen credentials appears to be one of the ways malware propagates across different systems.
Further technical details on Kobalos are available at this link sul WeLiveSecurity.






