LINUX-BASED APACHE MALWARE INFECTIONS: BITING THE HAND THAT SERVES US ALL
Cathal Mullaney · 2014
In May 2011, we investigated a persistent malware infection specifi c to a Linux installation of the Apache web server. The infection was unique in that it used Apache’s own APIs as a means to attack and infect unsuspecting clients. This attack vector was unusual as it did not target static web pages with an iframe or JavaScript injection. Instead, every web page served to a client’s browser was dynamically modifi ed to contain malicious content. By leveraging the Apache module APIs and Apache fi ltering framework, attackers were capable of serving malware to thousands of targeted users. Originally classifi ed as Trojan.Apmod, the malware re-emerged in 2012 as Linux.Chapro and was ultimately identifi ed as a component of the Darkleech exploit kit. During the past year, tens of thousands of active infections have been identifi ed, ranging from private businesses to educational institutions and the web servers of prominent security vendors. What fi rst appeared to be a targeted attack has since been identifi ed as one of a growing number of Linux malware infections. These infections, targeting Linux installations of the Apache web server, have proven to be a perfect vector for serving malware on a global scale. This paper will demonstrate that targeting Linux-based Apache web servers is an active and extremely effective method of malware infection. We present an overview of Linux malware and a technical analysis of two Apache-based infections, Trojan.Apmod and Linux.Chapro. We discuss common infection vectors for Linux servers, the payload infection chain, and fi nal payloads distributed to clients.