Skip to content

Comment on AURpocalypse now: a look at the recent AUR attacksparent

Comments

you can't rely on "watch for anomalies" with your human eyes

Yes, I agree, that's a good call. I would not try to check for anomalies manually with meatware. I would parse the data with python regex tools to establish a baseline and search for anomalous patterns.

I edited my post to reflect the change you suggested.

Also bear in mind, that many rootkits hide processes and connections from command line tools like ps, top, lsof, netstat, ss, etc...

In this particular malware campaign, the malware contained a rootkit which hid precisely some of its activity:

https://github.com/gustavo-iniguez-goya/decloaker/discussion...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.