Malware infecting widely used security appliance survives firmware updates

TL;DR

Threat actors with a connection to the Chinese government are infecting a widely used security appliance from SonicWall with malware that remains active even after the device receives firmware updates, researchers said. local559b9ae2a578e1258e80c45a5794c071Boot persistence for firewalld/bin/iptabled8dbf1effa7bc94fc0b9b4ce83dfce2e6Redundant main malware process/bin/geoBotnetd619769d3d40a3c28ec83832ca521f521Firmware backdoor script/bin/ifconfig6fa1bf2e427b2defffd573854c35d4919Graceful shutdown scriptfirewalld, which executes its primary loop once for a count of every file on the system squared: …for j in $(ls / -R) do for i in $(ls / -R) do:… The script is responsible for executing an SQL command to accomplish credential stealing and execution of the other components. The researchers said they didn't know what the initial infection vector was

Like summarized versions? Support us on Patreon!