in my script kid days, ( 30 years ago ) I did something similar for linux , using raw sockets and I think with ETH_P_ALL. embedding into a an already existing regular linux process ( recompiling the source code ) the problem was high cpu usage of the process when network usage was intensive. of course it did't survive when the OS updated the program.
This is very cool. Definitely seems like either an early or one-time, targeted attack by someone with good know-how and significant resources, even if it itself is not top-tier. Pretty cool find!
Nothing, because blackhat activity disqualifies itself from such a label. Recognition is actively withheld since it'd encourage some bad actors. Same reason malicious software is always given a different name even if one can be found in it.
4 comments