As reported by Cyber Insider, a free Linux server management tool called FirewallFalcon has been discovered secretly hijacking network traffic, giving its developer unauthorized control over installed systems. This tool, primarily promoted to VPN resellers and operators of "free internet" services, combines legitimate functions with malicious components, according to Flare researchers.Researchers identified that FirewallFalcon Manager secretly redirects traffic, weakens server security, and in older versions, installs a universal SSH backdoor. The campaign was uncovered by Flare cybersecurity researcher Assaf Morag after a honeypot server was compromised and used to deploy FirewallFalcon. The tool is advertised as an open-source solution for managing VPN, proxy, and SSH tunneling infrastructure, targeting operators in emerging markets.A critical component, DT Tunnel, is modified to redirect traffic to an IP address controlled by the FirewallFalcon operator. This is achieved by adding a custom root certificate and altering the /etc/hosts file, creating a man-in-the-middle position. Earlier versions were more aggressive, collecting server information and creating privileged SSH accounts. Flare highlighted how such software supply chain attacks can infiltrate underground ecosystems, urging administrators to be cautious of tools that modify system settings and communicate with external servers.Source: Cyber Insider
Network Security
FirewallFalcon tool found hijacking network traffic
An In-Depth Guide to Network Security
Get essential knowledge and practical strategies to fortify your network security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
