ATT&CKSoftwareLinux Rabbit

Linux Rabbit

S0362

Malware.View on attack.mitre.org

About this malware

Linux Rabbit is malware that targeted Linux servers and IoT devices in a campaign lasting from August to October 2018. It shares code with another strain of malware known as Rabbot. The goal of the campaign was to install cryptocurrency miners onto the targeted servers and devices.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1033
System Owner/User Discovery

Linux Rabbit opens a socket on port 22 and if it receives a response it attempts to obtain the machine's hostname and Top-Level Domain.

T1078
Valid Accounts

Linux Rabbit acquires valid SSH accounts through brute force.

T1110.003
Password Spraying

Linux Rabbit brute forces SSH passwords in order to attempt to gain access and install its malware onto the server.

T1132
Data Encoding

Linux Rabbit sends the payload from the C2 server as an encoded URL parameter.

T1133
External Remote Services

Linux Rabbit attempts to gain access to the server via SSH.

T1546.004
Unix Shell Configuration Modification

Linux Rabbit maintains persistence on an infected machine through rc.local and .bashrc files.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Anomali Linux Rabbit 2018 Open source
    Anomali Labs. (2018, December 6). Pulling Linux Rabbit/Rabbot Malware Out of a Hat. Retrieved March 4, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.