Unveiling sedexp: A Stealthy Linux Malware Exploiting udev Rules
Essential information
- Published
- 23/08/2024 09:39
- Modified
- 23/08/2024 10:00
- Tags
- 2024-08-23 concealment evasion linux persistence reverse shell sedexp
- Related entities
- 3 observables, 9 techniques (mitre), 1 malware
Description
Stroz Friedberg discovered sedexp, a stealthy Linux malware that utilizes udev rules to achieve persistence and evade detection. It provides reverse shell capabilities and advanced concealment tactics. Employed by a financially motivated threat actor, sedexp hides credit card scraping code, indicating a focus on financial gain. Despite being active since 2022, multiple public instances had zero detections, highlighting its evasive nature.