The National Security Agency (NSA) and the FBI have issued a warning against new Linux malware called "Drovorub" which was allegedly developed by Russian military hackers.
According to a report based on data collected by the agencies, the Linux malware strain is the work of APT28, a notorious hacking group from Military Unit 26165 of the General Intelligence Directorate of the Russian General Staff ( GRU) 85th Main SpecialService Center (GTsSS). The intent behind the spread of malware is espionage and theft of secrets from the public sector and IT companies.
Drovorub Linux malware
The Drovorub Linux malware, according to the two agencies, consists of an implant, a file transfer tool, a kernel module rootkit, a command and control server and a port forwarding. The report mentions that the malware is very stealthy and may successfully go undetected on machines thanks to advanced rootkit technologies deployed by hackers. The stealth capabilities of Drovorub Linux malware make it easy for hackers to target different types of platforms, launching attacks at any time.
The report describes the operation of each component of the Linux malware that communicates with each other using JSON through WebSockets and the traffic is encrypted from the server module using the RSA algorithm.



Source: NSA How to protect yourself from Drovorub Linux malware?
The NSA and the FBI have implemented a few precautionary measures that could be used to protect against the new strain of Linux malware:
- Keep all Linux systems updated to kernel version 3.7 or later.
- Systems must be configured to load modules with digital signatures.
- Enable the UEFI Secure Boot verification mechanism.
