Drovorub
Description
(NSA/FBI) Drovorub is a Linux malware toolset consisting of an implant coupled with a kernel module rootkit, a file transfer and port forwarding tool, and a Command and Control (C2) server. When deployed on a victim machine, the Drovorub implant (client) provides the capability for direct communications with actor-controlled C2 infrastructure; file download and upload capabilities; execution of arbitrary commands as ‘root’; and port forwarding of network traffic to other hosts on the network.
Names
Name |
---|
Drovorub |
Category
Malware
Type
- Rootkit
- Backdoor
- Exfiltration
- Tunneling
Information
- https://media.defense.gov/2020/Aug/13/2002476465/-1/-1/0/CSA_DROVORUB_RUSSIAN_GRU_MALWARE_AUG_2020.PDF
- https://www.mcafee.com/blogs/other-blogs/mcafee-labs/on-drovorub-linux-kernel-security-best-practices/
Mitre Attack
Other Information
Uuid
0b0244ac-36ac-413d-af90-ffcdc3ef80cb
Last Card Change
2022-12-30