SysJoker backdoor masquerades as benign updates. [Research Saturday]

Published: Feb. 12, 2022, 8 a.m.

Guests Avigayil Mechtinger and Ryan Robinson from Intezer discuss SysJoker malware, a backdoor that targets Windows, Linux and MacOS, Malware targeting multiple operating systems has become no exception in the malware threat landscape.\xa0Vermilion Strike, which was documented just last September, is among the latest examples until now.\xa0\xa0\nIn December 2021, the team at Intezer discovered a new multi-platform backdoor that targets Windows, Mac, and Linux. The Linux and Mac versions are fully undetected in VirusTotal. Intezer named this backdoor\xa0SysJoker.\nSysJoker was first discovered during an active attack on a Linux-based web server of a leading educational institution. After further investigation, Intezer found that SysJoker also has Mach-O and Windows PE versions. Based on Command and Control (C2) domain registration and samples found in VirusTotal, Intezer estimates that the SysJoker attack was initiated during the second half of 2021.\xa0\xa0\nThe research can be found here:\nNew SysJoker Backdoor Targets Windows, Linux, and macOS\n\nLearn more about your ad choices. Visit megaphone.fm/adchoices