HACKING
Microsoft engineer spots Linux back door
In late March, Microsoft software engineer Andres Freund noticed a tiny delay when logging in via SSH, and uncovered a mysterious back door.
The pattern of this attack superficially resembles that of APT29, aka Cozy Bear, who has links to Russian foreign intelligence.
CREDIT: Wikimedia/Public domain, United States Computer Emergency Readiness Team
In late March 2024, Microsoft software engineer Andres Freund was flying home to San Francisco from his native Germany. He’d been doing some micro benchmarking and saw that his system’s sshd processes were using an unusual amount of CPU resources. This in turn was generating a number of errors in Valgrind.