{"id":27195,"date":"2019-05-23T18:30:46","date_gmt":"2019-05-23T18:30:46","guid":{"rendered":"https:\/\/www.microsoft.com\/security\/blog\/?p=89464"},"modified":"2019-05-23T18:30:46","modified_gmt":"2019-05-23T18:30:46","slug":"uncovering-linux-based-cyberattack-using-azure-security-center","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/uncovering-linux-based-cyberattack-using-azure-security-center\/","title":{"rendered":"Uncovering Linux based cyberattack using Azure Security Center"},"content":{"rendered":"<p>As more and more enterprises move to the cloud, they also bring their own set of security challenges. Today, almost half of Azure virtual machines (VMs) are running on&nbsp;Linux, and as the Linux server population grows, so are the attacks targeting them. As detection capabilities advance, attackers are using new and stealthier&nbsp;techniques to stay undetected and persist with their motives. Azure Security Center, Microsoft\u2019s cloud-based cyber solution,&nbsp;helps customers safeguard their cloud workloads as well as protect them from&nbsp;these threats.<\/p>\n<p>In this blog post, we detail a real-world Linux attack whose purpose initially looked like crypto mining, but it turned out that the attacker\u2019s intent was to use the compromised host as a launchpad for further large-scale attacks.<\/p>\n<h3>Incident details<\/h3>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-89466\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/Azure-Security-Center-1.png\" alt width=\"1062\" height=\"682\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/Azure-Security-Center-1.png 1062w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/Azure-Security-Center-1-300x193.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/Azure-Security-Center-1-768x493.png 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/Azure-Security-Center-1-1024x658.png 1024w\" sizes=\"auto, (max-width: 1062px) 100vw, 1062px\"><\/p>\n<p>After the initial successful SSH brute force compromise, the attacker proceeds to download a first stage \u2018tddwrt7s.sh\u2019 script using utilities like \u2018wget\u2019 that delivers further payload to the host. Azure Security Center surfaces this behavior via a \u201cDetected suspicious file download\u201d alert.<\/p>\n<p>Post stage 1 download, the attacker executed the script to find \u2018dota.tar.gz\u2019 by enumerating multiple hosting URLs. Once a live hosting IP was found, the second stage file gets delivered in directory \u2018\/tmp\/.mountfs.\u2019 Most of these exploitation and persistence techniques are observed from the \/tmp folder. In this case all activities were tracked under \/tmp\/.mountfs and \/tmp\/.mountfs\/.rsync directories. Creating directories with a dot keeps the activity hidden from the user interface, a common technique used by attackers.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/Azure-Security-Center-2b.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-89467\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/Azure-Security-Center-2b.png\" alt width=\"800\" height=\"609\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/Azure-Security-Center-2b.png 1500w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/Azure-Security-Center-2b-300x228.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/Azure-Security-Center-2b-768x585.png 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/Azure-Security-Center-2b-1024x780.png 1024w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\"><\/a><\/p>\n<p>Later, we see traffic to different mining pools including \u2018mine.moneropool.com\u2019 but nothing further that would confirm the purpose as mining cryptocurrency. The \u201cDetected suspicious network activity\u201d analytic triggered on this activity along with \u201cDigital currency mining\u201d analytic. This was followed by reconnaissance grep activity used by the attacker to get more information on the target machine to see if it had already been compromised and in use by other actors.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/screenshot2.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-89476 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/screenshot2.png\" alt width=\"483\" height=\"798\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/screenshot2.png 483w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/screenshot2-182x300.png 182w\" sizes=\"auto, (max-width: 483px) 100vw, 483px\"><\/a><\/p>\n<p>The attackers then used a bash script to search and kill processes on some of the above-mentioned miners that they grepped using command:<\/p>\n<p>\u201cps auxf|grep -v grep|grep \u201cxmrig\u201d | awk \u2018{print $2}\u2019|xargs kill -9\u201d<\/p>\n<p>Let\u2019s talk more about what this command does. The first command helps to show a tree view of parent-child processes in the output of ps (process status).The first grep removes the grep process from this list and the second grep will extract any xmrig (a well-known miner) process in the filtered list. Awk pattern matches the specified pattern and xargs executes the SIGKILL signal.<\/p>\n<p>What follows next is a series of pkill commands to kill processes using couple of techniques that:<\/p>\n<ol>\n<li>Match the entire process and argument list pattern.<\/li>\n<li>Forcefully terminate a process.<\/li>\n<\/ol>\n<p>To get the maximum CPU usage and efficiency, attackers generally start deleting the existing coin miner instances and focus on deploying new instances of mining payload.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/screenshot1.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-89475 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/screenshot1.png\" alt width=\"519\" height=\"853\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/screenshot1.png 519w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/screenshot1-183x300.png 183w\" sizes=\"auto, (max-width: 519px) 100vw, 519px\"><\/a><\/p>\n<p>Generally, after this activity, the traces of cryptocurrency wallet or other activities related to mining becomes evident but what followed next was a little surprise.<\/p>\n<p>It turns out that this machine appeared to have been used to target 20,000 different endpoints based on our timeline of attack analysis detailed below:<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/Azure-Security-Center-5b.png\" target=\"_blank\" rel=\"noopener noreferrer\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-89468\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/Azure-Security-Center-5b.png\" alt width=\"800\" height=\"623\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/Azure-Security-Center-5b.png 1500w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/Azure-Security-Center-5b-300x234.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/Azure-Security-Center-5b-768x598.png 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/Azure-Security-Center-5b-1024x797.png 1024w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\"><\/a><\/p>\n<p>Azure Security Center caught most of the suspicious activities observed above that triggered security alerts. To further our investigation, we collaborated with our internal memory forensics team. The analysis of the ELF payload unfolded even more details in this attack campaign:<\/p>\n<ul>\n<li>The payload had three important components:\n<ul>\n<li>tsm64: An ELF executable.<\/li>\n<li>Libraries that tsm64 relied on for execution.<\/li>\n<li>tsm: Code used to launch the tsm64 executable.<\/li>\n<\/ul>\n<\/li>\n<li>To ensure that the attacker payload was able to run on most distributions, the attackers supplied the libraries tsm64, which was dependent on for successful execution.<\/li>\n<li><strong>tsm:<\/strong> tsm is ld.so renamed. ld.so is a helper program that loads the shared libraries needed by the program executable, prepares the program to run, and then runs it.<\/li>\n<li><strong>Dependent libraries:<\/strong> The dependency analysis of the tsm64 executable showed that it needed four libraries at the runtime. Namely, libpthread.so.0, libdl.so.2, libc.so.6, and ld-linux-x86-64.so.2.<\/li>\n<li><strong>tsm64:<\/strong> This is the executable that the attacker eventually wants to run. Turns out, tsm64 is a multi-threaded SSH brute force tool that can attack a set of IP\u2019s with provided passwords.<\/li>\n<li>The analysis of the Procedure Linkage Table (PLTs) for tsm64 showed the multi-threaded, network communication, and password file reading capabilities. A subset of the system apis are listed below:\n<ul>\n<li><strong>Networking:<\/strong> setsockopt, getsockopt, getsockname, connect, gethostname, socket, inet_ntoa, recvfrom, recv, bind, getaddrinfo, inet_pton, getpeername<\/li>\n<li><strong>Multi-threaded (pthread):<\/strong> pthread_getspecific, pthread_setspecific, pthread_cond_signal, pthread_mutex_init, pthread_create, pthread_cond_init, pthread_key_delete, pthread_self, pthread_join, pthread_equal, pthread_cond_wait, pthread_detach, pthread_once, pthread_mutex_lock, pthread_key_create, pthread_mutex_destroy, pthread_cond_broadcast, pthread_mutex_unlock, pthread_kill<\/li>\n<li><strong>Password file entry:<\/strong> getpwnam, getpwnam_r, getpwuid_r<\/li>\n<\/ul>\n<\/li>\n<li>The IP address list and user credentials to be used for the brute force attack were downloaded into innocuous sounding file names \u2018a\u2019 and \u2018b.\u2019 File \u2018a\u2019 contained a list of 20,000 different IP addresses while file \u2018b\u2019 had a listing of credentials. These files were later renamed to \u2018ip\u2019 and \u2018p\u2019 respectively and passed into tsm64.<\/li>\n<li>Using the inbuilt timeout utility, the tool was programmed to run for a maximum time of 90 minutes.<\/li>\n<\/ul>\n<p>Adversaries are always finding new and novel ways to evade detection. As cyber defenders, we need to constantly innovate and track these latest threats in order to thwart new and deceptive attacks that are making rounds in the cloud cyber world.<\/p>\n<h3>Recommended actions<\/h3>\n<ul>\n<li>Azure Security Center can automatically correlate such multiple triggered alerts into a single <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/security-center-incident\" target=\"_blank\" rel=\"noopener noreferrer\">security incident<\/a>. This capability provides a single overview of any attack campaign and all the related alerts to understand the action attackers took and what resources were impacted.<\/li>\n<li>While Azure Security Center alerted on the activity, the intrusion could have been prevented through good password hygiene. It\u2019s recommended to utilize passwords and passphrases that are not easily guessed. Some of our previous blogs cover this topic: <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/security-center-just-in-time\" target=\"_blank\" rel=\"noopener noreferrer\">Just In Time (JIT)<\/a> , <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/Azure-Active-Directory-Identity\/Announcing-password-less-login-identity-governance-and-more-for\/ba-p\/262472\" target=\"_blank\" rel=\"noopener noreferrer\">Password-less sign-in<\/a>, and <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/key-vault\/key-vault-whatis\" target=\"_blank\" rel=\"noopener noreferrer\">Azure Key Vault<\/a>.<\/li>\n<li>Azure Security Center alerts can also be integrated in <a href=\"https:\/\/azure.microsoft.com\/en-us\/blog\/integrate-azure-security-center-alerts-into-siem-solutions\/\" target=\"_blank\" rel=\"noopener noreferrer\">existing SIEM solution<\/a> for a centralized view of security posture across your organization or with Microsoft\u2019s new SIEM <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/connect-azure-security-center\" target=\"_blank\" rel=\"noopener noreferrer\">Azure Sentinel<\/a>.<\/li>\n<\/ul>\n<h3>Learn more<\/h3>\n<p>To learn more about the Azure Security Center, see the following:<\/p>\n<p>READ MORE <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2019\/05\/23\/uncovering-linux-based-cyberattack-using-azure-security-center\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As detection capabilities advance, attackers are using new and stealthier techniques to stay undetected and persist with their motives. Azure Security Center, Microsoft\u2019s cloud-based cyber solution helps customers safeguard their cloud workloads as well as protect them from these threats.<br \/>\nThe post Uncovering Linux based cyberattack using Azure Security Center appeared first on Microsoft Security. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":27196,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[6426,6432],"class_list":["post-27195","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure","tag-azure-security","tag-security-management"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Uncovering Linux based cyberattack using Azure Security Center 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/uncovering-linux-based-cyberattack-using-azure-security-center\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Uncovering Linux based cyberattack using Azure Security Center 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/uncovering-linux-based-cyberattack-using-azure-security-center\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2019-05-23T18:30:46+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/06\/uncovering-linux-based-cyberattack-using-azure-security-center.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1062\" \/>\n\t<meta property=\"og:image:height\" content=\"682\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uncovering-linux-based-cyberattack-using-azure-security-center\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uncovering-linux-based-cyberattack-using-azure-security-center\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Uncovering Linux based cyberattack using Azure Security Center\",\"datePublished\":\"2019-05-23T18:30:46+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uncovering-linux-based-cyberattack-using-azure-security-center\\\/\"},\"wordCount\":1080,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uncovering-linux-based-cyberattack-using-azure-security-center\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/06\\\/uncovering-linux-based-cyberattack-using-azure-security-center.png\",\"keywords\":[\"Azure Security\",\"Security management\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uncovering-linux-based-cyberattack-using-azure-security-center\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uncovering-linux-based-cyberattack-using-azure-security-center\\\/\",\"name\":\"Uncovering Linux based cyberattack using Azure Security Center 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uncovering-linux-based-cyberattack-using-azure-security-center\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uncovering-linux-based-cyberattack-using-azure-security-center\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/06\\\/uncovering-linux-based-cyberattack-using-azure-security-center.png\",\"datePublished\":\"2019-05-23T18:30:46+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uncovering-linux-based-cyberattack-using-azure-security-center\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uncovering-linux-based-cyberattack-using-azure-security-center\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uncovering-linux-based-cyberattack-using-azure-security-center\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/06\\\/uncovering-linux-based-cyberattack-using-azure-security-center.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/06\\\/uncovering-linux-based-cyberattack-using-azure-security-center.png\",\"width\":1062,\"height\":682},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uncovering-linux-based-cyberattack-using-azure-security-center\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Azure Security\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/azure-security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Uncovering Linux based cyberattack using Azure Security Center\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Uncovering Linux based cyberattack using Azure Security Center 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/uncovering-linux-based-cyberattack-using-azure-security-center\/","og_locale":"en_US","og_type":"article","og_title":"Uncovering Linux based cyberattack using Azure Security Center 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/uncovering-linux-based-cyberattack-using-azure-security-center\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2019-05-23T18:30:46+00:00","og_image":[{"width":1062,"height":682,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/06\/uncovering-linux-based-cyberattack-using-azure-security-center.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/uncovering-linux-based-cyberattack-using-azure-security-center\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/uncovering-linux-based-cyberattack-using-azure-security-center\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Uncovering Linux based cyberattack using Azure Security Center","datePublished":"2019-05-23T18:30:46+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/uncovering-linux-based-cyberattack-using-azure-security-center\/"},"wordCount":1080,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/uncovering-linux-based-cyberattack-using-azure-security-center\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/06\/uncovering-linux-based-cyberattack-using-azure-security-center.png","keywords":["Azure Security","Security management"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/uncovering-linux-based-cyberattack-using-azure-security-center\/","url":"https:\/\/www.threatshub.org\/blog\/uncovering-linux-based-cyberattack-using-azure-security-center\/","name":"Uncovering Linux based cyberattack using Azure Security Center 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/uncovering-linux-based-cyberattack-using-azure-security-center\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/uncovering-linux-based-cyberattack-using-azure-security-center\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/06\/uncovering-linux-based-cyberattack-using-azure-security-center.png","datePublished":"2019-05-23T18:30:46+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/uncovering-linux-based-cyberattack-using-azure-security-center\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/uncovering-linux-based-cyberattack-using-azure-security-center\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/uncovering-linux-based-cyberattack-using-azure-security-center\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/06\/uncovering-linux-based-cyberattack-using-azure-security-center.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/06\/uncovering-linux-based-cyberattack-using-azure-security-center.png","width":1062,"height":682},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/uncovering-linux-based-cyberattack-using-azure-security-center\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Azure Security","item":"https:\/\/www.threatshub.org\/blog\/tag\/azure-security\/"},{"@type":"ListItem","position":3,"name":"Uncovering Linux based cyberattack using Azure Security Center"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/27195","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=27195"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/27195\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/27196"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=27195"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=27195"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=27195"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}