Proprietary 2020-01-24 · 708 days ·Backdoor, Credential Theft, Data Theft

Free Download Manager Linux page served backdoor

Free Download Manager's Linux download page intermittently redirected users to a malicious Debian package. The package installed a DNS-controlled backdoor and credential stealer.

Story

The Free Download Manager case was quiet because the compromise was selective. Linux users who clicked the official download page could receive either the real package or a malicious .deb from deb.fdmpkg.org. Kaspersky found video evidence of the redirection, and the vendor later confirmed a compromised page in its own backups.

The modified page chose between the legitimate link and the fake domain. The vendor said the attacker used an exception list for IP ranges associated with Bing and Google, so search crawlers saw clean behavior. That explains the long dwell time. The site looked normal to many visitors and to some automated checks.

The malicious Debian package used its postinst script as the insertion point. On install, it dropped /var/tmp/crond and /var/tmp/bs, then created /etc/cron.d/collect to run the backdoor every ten minutes. The installed Free Download Manager build itself traced to a January 24, 2020 release, while comments in the malicious script used Russian and Ukrainian and mentioned January 26 and 27 changes.

The backdoor resolved generated *.u.fdmpkg.org names and decoded the DNS response into a secondary server and port. It then opened a reverse shell over TCP or delegated SSL communication to /var/tmp/bs. In Kaspersky's sandbox, attackers used that shell to deploy a Bash stealer that collected system details, browser data, saved passwords, crypto wallets, and cloud credentials, then uploaded results with /var/tmp/atd.

Affected Artifacts

Observed
2020-01-24 to 2022-01-01
Compromised Versions
Unknown
Fixed
Not listed
Hashes
  • sha256:b77f63f14d0b2bde3f4f62f4323aad87194da11d71c117a487e18ff3f2cd468d
  • sha256:2214c7a0256f07ce7b7aab8f61ef9cbaff10a456c8b9f2a97d8f713abd660349
  • sha256:93358bfb6ee0caced889e94cd82f6f417965087203ca9a5fce8dc7f6e1b8a3ea
  • +1 more
  • Affected Free Download Manager scope covered specific Linux Debian packages distributed via malicious redirect from 2020 through 2022.
  • The vendor said the issue affected a small subset of Linux download attempts and did not affect Windows or macOS users.

Incident Context

Motive
Financial Gain Data Theft
Attribution
Group
Cause
Website Compromise
Transitive
No
Actor
Cybercriminal group

External References

Source record: proprietary/freedownloadmanager/meta.yaml