NerbianRAT Linux Malware
Summary
The hackers target a range of devices and services, including Ivanti Connect Secure (CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, CVE-2024-21893), Apache ActiveMQ, ConnectWise ScreenConnect, Qlik Sense (CVE-2023-41265, CVE-2023-41266, CVE-2023-48365) and Magento (CVE-2022-24086). The Magnet Goblin utilizes these vulnerabilities to infiltrate servers with tailored malware, such as NerbianRAT and MiniNerbian, along with a customized version of the WARPWIRE JavaScript stealer. Moreover, implementing additional measures like network segmentation, endpoint protection, and multi-factor authentication can reduce the impact of potential breaches. Its functionality encompasses executing commands from the C2 and transmitting results, updating activity schedules (for full days or specific hours), and adjusting configurations. Unlike the more intricate NerbianRAT, MiniNerbian communicates with the C2 through HTTP instead of raw TCP sockets, potentially indicating that it serves as a choice for redundancy or as a covert backdoor in specific scenarios by Magnet Goblin.