Decade of the RATs – Custom Chinese Linux Rootkits for Everyone

No ratings

Presented at BlackHat USA 2020 by

While 2020 is the Year of the Rat for the Chinese, it's felt more like the Decade of the RATs. In this talk, I reveal a nearly decade-long, undetected, state-sponsored effort to strategically target the Linux servers that comprise the backbone of modern-day government and industry. Having discovered a full stack of handcrafted, tailored, Linux malware, from interactive installation script to kernel rootkits to the attacker's control panel, I was able to construct a rare and uniquely detailed narrative of a concerted espionage effort.The talk reveals how five Chinese APT groups that originally stemmed from the notorious WINNTI collective formed a Linux splinter cell. Set against the backdrop of recent, renewed efforts by the US Department of Justice to expose and prosecute Chinese espionage, the talk sheds light on a new and troubling chapter in an otherwise old story of Chinese IP theft - one that crosses into the Android and Windows platforms as well. The talk demonstrates how the attackers successfully preyed upon defender assumptions regarding the security of Linux, the treatment of Windows adware, and the overall deployment of security products and services.Finally, attendees will also encounter new and intriguing questions, including:Is a Chinese APT group behind the development of one of the most widely used, commercially available RATs for mobile?Is WINNTI responsible for the creation of the largest known Linux DDoS botnet?