Drovorub

Description

(NSA/FBI) Drovorub is a Linux malware toolset consisting of an implant coupled with a kernel module rootkit, a file transfer and port forwarding tool, and a Command and Control (C2) server. When deployed on a victim machine, the Drovorub implant (client) provides the capability for direct communications with actor-controlled C2 infrastructure; file download and upload capabilities; execution of arbitrary commands as ‘root’; and port forwarding of network traffic to other hosts on the network.

Names

Name
Drovorub

Category

Malware

Type

  • Rootkit
  • Backdoor
  • Exfiltration
  • Tunneling

Information

Mitre Attack

Other Information

Uuid

0b0244ac-36ac-413d-af90-ffcdc3ef80cb

Last Card Change

2022-12-30