A reported Free Download Manager supply chain attack redirected Linux users to a malicious Debian package repository that installed information-stealing malware.

The malware used in this campaign establishes a reverse shell to a C2 server and installs a Bash stealer that collects user data and account credentials.

Kaspersky discovered the potential supply chain compromise case while investigating suspicious domains, finding that the campaign has been underway for over three years.

90 points

Now I need to know who the hell has installed Free Download Manager on Linux.

permalink
report
reply
7 points

It’s still my favorite download manager on Windows. It often downloads file significantly faster than the download manager built into browsers. Luckily I never installed it on Linux, since I have a habit of only installing from package managers.

Do you know of a good download manager for Linux?

permalink
report
parent
reply
7 points

How much faster are we talking?

I’ve honestly never looked at my downloads and though huh you should be quicker, well maybe in 90’s.

permalink
report
parent
reply
5 points

just grabbed a gig file - it would take about 8 minutes with a standard download in Firefox. Use a manager or axel and it will be 30 seconds. Then again speed isnt everything, its also nice to be able to have auto retry and completion.

permalink
report
parent
reply
4 points

FDM does some clever things to boost download speeds. It splits up a download into different chuncks, and somehow downloads them concurrently. It makes a big difference for large files (for example, Linux ISOs).

permalink
report
parent
reply
4 points

JDownloader, XDM, FileCentipede (this one is the closest to IDM, although it uses closed source libraries), kGet, etc.

permalink
report
parent
reply
2 points
*
Removed by mod
permalink
report
parent
reply
1 point

axel. use axel -n8 to make 8 connections/segments which it will assemble when it is done

permalink
report
parent
reply
1 point

Even with wget, wget -c can resume some downloads.

permalink
report
parent
reply
4 points

Or what is Free Download Manager

permalink
report
parent
reply

Gotta admit, it was me. I’ve only used a computer for short time.
I’ve got my first laptop 3 years ago, and that broke after just 2 months. And anyway, with AMD Athlon 64 it greatly struggled with a browser. So really I only started seriously using computer at the start of 2021, when I got another, usable laptop. And that’s when I downloaded freedownloadmanager.deb. Thankfully, I didn’t get that redirect, so it was a legitimate file.

permalink
report
parent
reply
2 points

I once did.

permalink
report
parent
reply
28 points

The article mentions how to check for infection:

If you have installed the Linux version of the Free Download Manager between 2020 and 2022, you should check and see if the malicious version was installed.

To do this, look for the following files dropped by the malware, and if found, delete them:

/etc/cron.d/collect
/var/tmp/crond
/var/tmp/bs
permalink
report
reply

Also you can check the .deb file’s postinst script. If it looks like shown here, no bueno.

permalink
report
parent
reply
25 points

“Non-free download manager”

permalink
report
reply
5 points

I had to essentially read the same thing four times before there was any new information in this post. Not sure if that’s a Jerboa thing or what, but probably could have been avoided.

permalink
report
reply
6 points

Yeah I agree, sorry about that. I thought that the body-text field was mandatory to fill in, so I used the introductory paragraph from the article so as not to editorialize.

permalink
report
parent
reply
4 points
*
Removed by mod
permalink
report
reply
2 points

I kind of disagree. Applications often require root permissions to install themselves, since regular users can’t access certain folders like /opt, etc.

Also, do you really think that people would actually read the source and then compile all their software themselves? Do you do the same?

Generally though I do agree, you’re probably fine installing software from your distro’s repos but even that’s not bulletproof and also it’s not like third-party repos are uncommon either.

permalink
report
parent
reply
1 point
*
Removed by mod
permalink
report
parent
reply

Linux

!linux@lemmy.ml

Create post

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word “Linux” in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

  • Posts must be relevant to operating systems running the Linux kernel. GNU/Linux or otherwise.
  • No misinformation
  • No NSFW content
  • No hate speech, bigotry, etc

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

Community stats

  • 43

    Monthly active users

  • 3.3K

    Posts

  • 19K

    Comments