179
submitted 10 months ago by neme@lemm.ee to c/linux@programming.dev
all 22 comments
sorted by: hot top controversial new old
[-] stevedidwhat_infosec@infosec.pub 121 points 10 months ago

Tl;Dr new Linux malware specific to a flavor used by the Indian government uses emojis as a c2 comms path

[-] s38b35M5@lemmy.world 61 points 10 months ago

The joke's on you, malware devs! I never use Discord, and never did on my Linux machines.

[-] joyjoy@lemm.ee 28 points 10 months ago

And it targets the BOSS environment, which is used by Indian officials.

[-] TheImpressiveX@lemmy.ml 29 points 10 months ago

BOSS environment

Bee Open Source Software?

[-] sorghum@sh.itjust.works 12 points 10 months ago

We talking about software for Haiku?

[-] RonSijm@programming.dev 20 points 10 months ago

I would assume this just relies on the Discord API being read by the bot - and not on having a local discord installed...

[-] devfuuu@lemmy.world 9 points 10 months ago

Let's see if the flatpak ideas about sandboxing being pushed down our throats actually prevent these abuses or not...

[-] MinusPi@pawb.social 6 points 10 months ago

I'm honestly so sick of everything being sandboxed. The security is not worth the hassle.

[-] Redjard@lemmy.dbzer0.com 16 points 10 months ago

More so, if it is easily sandboxed, it should just be a webapp. Which discord already is.
Just use the website.

Browsers are already easily themed, have plenty of tools to change deeper functionality, and are way more sandboxed than any other app packaging ecosystem.

[-] photonic_sorcerer@lemmy.dbzer0.com 4 points 10 months ago

I tried that, but I had problems with my audio setup every time I used it.

[-] kurumin@linux.community 2 points 10 months ago
[-] balder1993@programming.dev 3 points 10 months ago

That’s a good argument.

[-] Vilian@lemmy.ca 2 points 10 months ago
[-] MinusPi@pawb.social 15 points 10 months ago

Everything is ever so slightly broken in a way that I just can't ignore. Personalization doesn't quite work. Permissions are overwhelming and usually lead to silent failures. Integration with the rest of the system is weak at best.

[-] Vilian@lemmy.ca 0 points 10 months ago

so problems from programs that don't support flatpak, not flatpak fault, because everything you said is supported

Everything is ever so slightly broken in a way that I just can't ignore.

this isn't even caused by flatpak, it's the app fault

[-] MinusPi@pawb.social 3 points 10 months ago

I don't care whose fault it is, it's obnoxious and I don't want to bother with it. Lately though, it seems like everything is only being released as a flatpak app despite those issues.

[-] Catoblepas@lemmy.blahaj.zone 20 points 10 months ago

Asking as someone who is absolutely not tech proficient compared to most lemmy users: is this a vulnerability with Linux or Discord specifically, or is this something that could be carried out on any OS/messenger if the computer was infected?

[-] HuntressHimbo@lemm.ee 40 points 10 months ago

From the article, it sounds as though this isn't something a normal user should be worried about. They said the security researched believe it targets a Linux distribution used by the Indian government, and the phishing/malicious links seem intended to target Indian officials.

[-] homesweethomeMrL@lemmy.world 14 points 10 months ago

According to Volexity, the malware was discovered after the researchers spotted a UPX-packed ELF executable in a ZIP archive, likely distributed through phishing emails. Volexity believes that the malware targets a custom Linux distribution named BOSS that Indian government agencies use as their desktop.

I use Arch, btw. /s

[-] NateSwift@lemmy.dbzer0.com 31 points 10 months ago

It looks like there isn’t a vulnerability at all. Just a malware executable disguised as a pdf in a zip file that uses discord as a communication method

[-] Blaze@lemmy.zip 5 points 10 months ago

Interesting, thanks!

this post was submitted on 15 Jun 2024
179 points (95.9% liked)

Linux

6950 readers
570 users here now

A community for everything relating to the GNU/Linux operating system

Also check out:

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

founded 2 years ago
MODERATORS