WaterDrop Malware

General News

Summary

The WaterDrop malware is part of several recently discovered corrupted binaries used in attacks infecting Linux installations. Their analysis revealed that all of the threats used an open-source backdoor named Prism as a basis upon which modifications were slowly introduced by the attackers. Despite the prolonged usage, WaterDrop has managed to achieve and maintain a near-zero detection score, meaning that it has been able to fly under the radar for years without being noticed. So far, the most plausible explanation is that the high success rate was reached by keeping the attack campaign at an extremely small scale. The cybercriminals behind WaterDrop and its associated malware family have been updating their threatening toolkit slowly and are expected to continue their activities.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M