Looking Back on the Last Decade of Linux APT Attacks

2020-09-16 Intezer

https://www.intezer.com/blog/cloud-security/looking-back-on-the-last-decade-of-linux-apt-attacks/

Thumbnail for Looking Back on the Last Decade of Linux APT Attacks

Intezer surveys the rise of Linux-targeting APT campaigns and identifies North Korea as one of the major nation-state origins, alongside China, Russia, and the United States, in documented Linux espionage tooling from the prior decade. The source does not detail a specific Lazarus or DPRK intrusion chain, but it places North Korean activity within a broader trend of APTs porting Windows tooling to Linux or building cross-platform malware as Linux adoption grows across servers, cloud, and IoT. The report’s defensive takeaway is that Linux systems require dedicated visibility and runtime protection because offensive Linux capabilities are becoming more common and sophisticated across nation-state actors.

« Back