Beware of phishing emails delivering backdoored Linux VMs!

Share:

Unknown attackers are trying to trick Windows users into spinning up a custom Linux virtual machine (VM) with a pre-configured backdoor, Securonix researchers have discovered.

The campaign

The attack began with a phishing email, they believe, but they weren’t able to pinpoint the intendend victims.

The email included a link pointing to an unusually big ZIP file (285 MB), and its name – OneAmerica Survey.zip – points to the likely lure: a survey by OneAmerica Financial, a US company offering financial services.

“When the user extracts the archive, they’re presented with a single file (shortcut) ‘OneAmerica Survey’ and a ‘data’ directory containing the entire QEMU installation directory,” the researchers explained.

If the user clicks on the shortcut file, a process is started wherein:

  • The ZIP file is “unzipped” and its contents put into the user’s profile directory into a directory called “datax”
  • A batch processing (BAT) file is executed and it shows a decoy image saying there was an “Internal Server Error” while, in the background, a (renamed) QEMU process and command line is executed to start the emulated Tiny Core Linux environment

The customized Linux VM is meant to be used to create an interactive shell (essentially, a backdoor) on the host machine by initiating an SSH connection, through which the attackers can:

  • Download additional malicious payloads
  • Install additional tools on the machine
  • Rename files
  • Modify the system configuration
  • Do basic reconnaissance via system and user enumeration
  • Exfiltrate data

“Like a game of chess, the attackers prepped their environment with a strategy in mind. They systematically installed, tested, and executed multiple payloads and configurations, each preparing for the next phase,” the researchers noted.

“The use of bootlocal.sh and SSH keys indicates they’re aiming for a reliable presence on the machine. There were several times where they downloaded crondx files – pre-configured Chisel clients – from various URLs. The reasons for this were unknown, however we speculate that they could have been modifying the payload until it functions as expected.”

The Chisel client comes pre-configured so that it automatically connects to a specified command and control (C2) server via websockets, thus opening a persistent backdoor through which the attackers can access the compromised environments.

Evading detection

Traditional antivirus solutions generally can’t (or don’t by default) scan very large files, and they also can’t view what’s happening in the emulated Linux environment.

“Chisel’s design makes it particularly effective for creating covert communication channels and tunneling through firewalls, often under the radar of network monitoring tools,” the researchers added.

“The attacker’s reliance on legitimate software like QEMU and Chisel adds an additional layer of evasion, as these tools are unlikely to trigger alerts in many environments.”

Securonix has shared indicators of compromise associated with this campaign and advises organizations to monitor common malware staging directories, monitor for instances of legitimate software being executed from unusual locations, use robust endpoint logging to aid in PowerShell detections.

Zeljka Zorz

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
4:50 pm, Jun 29, 2025
weather icon 30°C
L: 28° | H: 31°
scattered clouds
Humidity: 44 %
Pressure: 1023 mb
Wind: 3 mph WSW
Wind Gust: 6 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 31%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:46 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
28° | 31°°C 0 mm 0% 8 mph 56 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
20° | 34°°C 0 mm 0% 7 mph 72 % 1022 mb 0 mm/h
Tue Jul 01 10:00 pm
weather icon
21° | 32°°C 0 mm 0% 14 mph 72 % 1017 mb 0 mm/h
Wed Jul 02 10:00 pm
weather icon
17° | 25°°C 1 mm 100% 9 mph 84 % 1019 mb 0 mm/h
Thu Jul 03 10:00 pm
weather icon
14° | 23°°C 0 mm 0% 8 mph 82 % 1025 mb 0 mm/h
Today 7:00 pm
weather icon
27° | 29°°C 0 mm 0% 2 mph 42 % 1022 mb 0 mm/h
Today 10:00 pm
weather icon
22° | 25°°C 0 mm 0% 8 mph 56 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
21° | 21°°C 0 mm 0% 7 mph 70 % 1022 mb 0 mm/h
Tomorrow 4:00 am
weather icon
20° | 20°°C 0 mm 0% 3 mph 72 % 1021 mb 0 mm/h
Tomorrow 7:00 am
weather icon
21° | 21°°C 0 mm 0% 4 mph 65 % 1020 mb 0 mm/h
Tomorrow 10:00 am
weather icon
27° | 27°°C 0 mm 0% 5 mph 44 % 1019 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
33° | 33°°C 0 mm 0% 6 mph 30 % 1017 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
34° | 34°°C 0 mm 0% 7 mph 24 % 1015 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,078.20
0.56%
Ethereum(ETH)
€2,082.32
0.49%
Tether(USDT)
€0.85
0.00%
XRP(XRP)
€1.87
-0.59%
Solana(SOL)
€129.00
2.65%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.139651
0.86%
Shiba Inu(SHIB)
€0.000010
1.05%
Pepe(PEPE)
€0.000009
2.05%
Scroll to Top