• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Artikel
  4. Uncovering linux desktop espionage
 
  • Details
  • Full
Options
July 2025
Journal Article
Title

Uncovering linux desktop espionage

Abstract
The increasing adoption of Linux-based desktop systems in various sectors, including critical infrastructures and personal use, has made them an attractive target for Advanced Persistent Threat (APT) groups and state actors. Yet, the espionage capabilities of Linux desktop malware and the forensic strategies for uncovering them remain largely unexamined. This paper addresses this gap by analyzing ten malware families that target the Linux desktop environment, studying the utilized espionage techniques, and introducing novel approaches to detect them using memory forensics.
Facing the multitude of espionage attack implementations that result from the diverse Linux desktop ecosystem, we propose to reduce the complexity of memory forensic investigations by focusing on the analysis of targeted core services. We evaluate our approach by implementing proof-of-concept Volatility plugins for identification of keylogging, screen capturing as well as camera and microphone recording malware, and prove their effectiveness by performing forensic analyses of real-world espionage techniques that were utilized during APT campaigns. Our evaluation shows that memory forensics is effective in uncovering Linux espionage attacks, and we are confident that our study provides valuable insights for future research and practical analysis of these threats.
Author(s)
Schmidt, Lukas
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Strasda, Sebastian
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Schinzel, Sebastian
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Journal
Forensic Science International : FSI. Digital Investigation  
Conference
Annual Digital Forensics Research Conference 2025  
Open Access
File(s)
Download (1.18 MB)
Rights
CC BY-NC-ND 4.0: Creative Commons Attribution-NonCommercial-NoDerivatives
DOI
10.1016/j.fsidi.2025.301921
10.24406/publica-7183
Additional link
Full text
Language
English
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024