Sunday, April 13, 2025
HomeLinux13 Million Security Incidents Were Attempted to Hack Linux Systems in 2021

13 Million Security Incidents Were Attempted to Hack Linux Systems in 2021

Published on

SIEM as a Service

Follow Us on Google News

Linux power systems are used in almost every platform including Super computers, high-speed trains even in space programs, and it dominates the cloud in which 96.3% of the top 1 million web servers are globally powered by Linux systems due to the stability, flexibility, and open-source.

Parallelly, cyber attack towards Linux powered systems are dramatically increased due to its contribution in every part of the technology and enterprise networks, where various flavors or distributions of Linux and Unix systems playing major roles.

Since Linux has a larger footprint, unknowingly systems administrators exposed their Linux systems, including the critical data open to the internet.

- Advertisement - Google News

Researchers from Trend Micro analyzed with the help of Censys.io, a search engine, through which they have reported that nearly 14 million Linux-powered systems are exposed to the internet and open to access for the hackers.

When diving deep into the exposed systems, researchers also found that a Secure Shell Protocol (SSH) for Linux-based machines was found open for almost 19 million systems facing the internet, and it help hackers to attack the exposed system using botnets to initiate the brakeforce attacks.

Linux Systems Affected by Top Malware Families & Vulnerabilities

In Deep analysis with the telemetry data collected by Trend Micro experts from January 2021, over 13 Million incidents were identified & recorded targeted by various malware families.

In this list, Coinminers are aggressively targeting the Linux-powered systems and Web Shells, Ransomware, Trojans, and other familiars observed next to it. These malware families are mainly targeting the following Linux distributions.

  • CentOS Linux
  • Cloud Linux Server
  • Ubuntu Server
  • RedHat Enterprise Linux Sever

There is some windows malware that has been added to this list, which means that the attackers using Linux servers as a Command & Control server or storage.

Vulnerabilities on Linux

Trend Micro Researchers uncovered the 15 most exploited vulnerabilities (Common Vulnerabilities and Exposures (CVEs)) that target Linux-powered systems with the bits of help of the telemetry data.

Apache Struts2 remote code execution (RCE) vulnerabilityCVE-2017-5638Critical
Apache Struts 2 REST plugin XStream RCE vulnerabilityCVE-2017-9805High
Drupal Core RCE vulnerabilityCVE-2018-7600Critical
Oracle WebLogic server RCE vulnerabilitiesCVE-2020-14750Critical
WordPress file manager plugin RCE vulnerabilityCVE-2020-25213Critical
vBulletin ‘subwidgetConfig’ unauthenticated RCE vulnerabilityCVE-2020-17496Critical
SaltStack salt authorization weakness vulnerabilityCVE-2020-11651Critical
Apache Struts OGNL expression RCE vulnerabilityCVE-2017-12611Critical
Eclipse Jetty chunk length parsing integer overflow vulnerabilityCVE-2017-7657Critical
Alibaba Nacos AuthFilter authentication bypass vulnerabilityCVE-2021-29441Critical
Atlassian Jira information disclosure vulnerabilityCVE-2020-14179Medium
Nginx crafted URI string handling access restriction bypass vulnerabilityCVE-2013-4547N/A
Apache Struts 2 RCE vulnerabilityCVE-2019-0230Critical
Apache Struts OGNL expression RCE vulnerabilityCVE-2018-11776High
Liferay portal untrusted deserialization vulnerabilityCVE-2020-7961Critical

During the investigation, out of 200 vulnerabilities, only 15 were actively exploited in wide or have existing proofs of concept.

According to the Trend Micro report “The applications affected by these 200 vulnerabilities have a few clear targets, including WordPress or Apache Struts, but services such as Atlassian JIRA, dnsmasq, and Alibaba Nacos aren’t the first ones a security expert would automatically assume to be in attackers’ crosshairs.”

Also, Web-based attacks on Linux systems are keep on increasing which is uncovered by researchers when comparing the spread of web and non-web attacks on Linux systems.

As result, 76% of the attacks are web-based, while only 24% of the attacks are non-web in nature that targeting the Linux environment.

“With Linux being the first choice for web servers and applications, the OWASP Top 10 has become more relevant to the operating system. Since 76.9% of the top 10 million web servers globally are Unix-based, the OWASP web app risks act as an important filter when looking at vulnerabilities affecting Linux/Unix systems.” Researchers said.

Another report revealed that injection vulnerabilities and Cross-Site scripting vulnerabilities took the first 2 places for performing the highest targeted attacks.

In terms of non-OWASP security risks, Layering brute-force, directory traversal, and request smuggling attacks took the first 3 places.

Secure Your Linux Environment

Trend Micro researchers suggested various security measures to protect your Linux environments using  native Linux tools and configurations of following:-

Third Party Tools & Control

  • Antimalware
  • Intrusion prevention/detection system (IPS/IDS)
  • Execution control
  • Configuration assessment
  • Vulnerability assessment and patching
  • Activity monitoring

Secure Your Container in Enterprise Environment

Following these basic Docker best practices that will help enterprises keep their containers secure:

  • Use lightweight base images such as Alpine Linux
  • Apply the principle of least privilege; don’t run containers as root or in privileged mode
  • Sign and verify container images to protect them against supply chain attacks
  • Actively scan and fix vulnerabilities in container dependencies
  • Don’t hardcode secrets or credentials on container images

Follow us on LinkedinTwitterFacebook for daily Cybersecurity News & Updates

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Threat Actors Manipulate Search Results to Lure Users to Malicious Websites

Cybercriminals are increasingly exploiting search engine optimization (SEO) techniques and paid advertisements to manipulate...

Hackers Imitate Google Chrome Install Page on Google Play to Distribute Android Malware

Cybersecurity experts have unearthed an intricate cyber campaign that leverages deceptive websites posing as...

Dangling DNS Attack Allows Hackers to Take Over Organization’s Subdomain

Hackers are exploiting what's known as "Dangling DNS" records to take over corporate subdomains,...

HelloKitty Ransomware Returns, Launching Attacks on Windows, Linux, and ESXi Environments

Security researchers and cybersecurity experts have recently uncovered new variants of the notorious HelloKitty...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

HelloKitty Ransomware Returns, Launching Attacks on Windows, Linux, and ESXi Environments

Security researchers and cybersecurity experts have recently uncovered new variants of the notorious HelloKitty...

Linux 6.15-rc1 Released: Better Drivers, Faster Performance

The Linux kernel community has witnessed another milestone with the release of Linux 6.15-rc1,...

Auto-Color Linux Backdoor: TTPs and Internal Architecture Exposed

A newly identified Linux backdoor named "Auto-Color," first observed between November and December 2024,...