Mumblehard Malware

Mumblehard is a strain of malware that primarily targets web servers running Linux and BSD operating systems and surreptitiously uses the infected systems as spamming bots.

The security firm ESET discovered the Mumblehard malware in April 2015, but there is evidence of the malware remaining under the radar for at least the past five years. ESET gave the malware the Mumblehard moniker because it “mutters spam from your servers,” according to the security research firm.

How Mumblehard Works and How to Prevent It from Starting

The Mumblehard malware exploits vulnerabilities in WordPress and Joomla to execute two components written in Perl. The first component is a backdoor that requests commands from the malware’s command and control server, and the second is a spammer daemon that can be launched via a command received by the backdoor.

In addition to exploiting vulnerabilities in WordPress and Joomla, the Mumblehard malware can also be installed through the distribution and installation of backdoored “pirated” versions of a Linux and BSD program called DirectMailer, which is a software tool used for sending out e-mails in bulk.

The Mumblehard malware backdoor is typically installed in the /tmp or /var/tmp directories, and ESET recommends mounting these directories with the noexec option to prevent the Mumblehard backdoor from being able to start. Those concerned with whether Mumblehard is already installed on a server should first look for unsolicited cronjob entries for all users on the server(s) suspected of being infected.

Forrest Stroud
Forrest Stroud
Forrest is a writer for Webopedia. Experienced, entrepreneurial, and well-rounded, he has 15+ years covering technology, business software, website design, programming, and more.
Get the Free Newsletter
Subscribe to Daily Tech Insider for top news, trends & analysis
This email address is invalid.
Get the Free Newsletter
Subscribe to Daily Tech Insider for top news, trends & analysis
This email address is invalid.

Related Articles

Embedded Analytics

Embedded analytics brings self-service business intelligence to everyday application users.

HRIS

Human resources information system (HRIS) solutions help businesses manage multiple facets of their workforce operations. They provide a central platform for human resources professionals...

Complete List of Cybersecurity Acronyms

Cybersecurity news and best practices are full of acronyms and abbreviations. Without understanding what each one means, it's difficult to comprehend the significance of...

Human Resources Management System

A Human Resources Management System (HRMS) is a software application that supports many functions of a company's Human Resources department, including benefits administration, payroll,...

ScalaHosting

ScalaHosting is a leading managed hosting provider that offers secure, scalable, and affordable...

HRIS

Human resources information system (HRIS) solutions help businesses manage multiple facets of their...

Best Managed Service Providers...

In today's business world, managed services are more critical than ever. They can...