New 64-bit Linux Rootkit Doing iFrame Injections
A few days ago, an interesting piece of Linux malware came up on the Full Disclosure mailing-list. It’s an outstanding sample, not only because it targets 64-bit Linux platforms and uses advanced techniques to hide itself, but primarily because of the unusual functionality of infecting the websites hosted on attacked HTTP server – and therefore working as a part of drive-by download scenario.
Read more: New 64-bit Linux Rootkit Doing iFrame Injections
Story added 26. November 2012, content source with full text you can find at link above.