Xubuntu website hacked, spreading cryptocurrency malware disguised as download package

The official Xubuntu site was hacked, spreading cryptocurrency malware via the xubuntu-safe-download.zip file, targeting users who recently switched from Windows 10 to Linux.

As many of you know, Windows 10 officially reached the end of support on October 14. For those who can't upgrade to Windows 11 due to inadequate hardware, a popular option is to switch to Linux — and hackers have been quick to take advantage of this trend.

 

Over the weekend, the official website of Xubuntu – an Ubuntu-based distribution – was hacked and injected with Windows malware into the download package.

According to OMG ! Ubuntu , the malware is hidden in a file ironically named xubuntu-safe-download.zip, which is downloaded by users trying to download the official .torrent file. If the user does not download the torrent, they will not be affected.

Inside this ZIP file is a malicious Windows executable (.exe) file along with a 'Terms of Use' text file. For experienced users, the presence of an .exe file instead of an .ISO or .IMG file would be a clear warning sign. However, those who have recently switched from Windows to Linux may not notice this and accidentally open the .exe file, infecting their computer.

Images 1 of Xubuntu website hacked, spreading cryptocurrency malware disguised as download package

Malware to steal cryptocurrency wallets

The malware's goal is to intercept and replace cryptocurrency wallet links that users copy to their clipboards — a common way to steal digital assets. Because cryptocurrency transactions are often unregulated and difficult to trace, it's virtually impossible for users to recover their funds if they're stolen.

The Xubuntu team shut down the compromised download site immediately after the incident was discovered to prevent others from being infected. The project also said it was accelerating the development of a new static site to replace the current aging WordPress platform.

Limited attack range

While the incident affected Xubuntu's reputation, the actual damage was relatively limited. No other Ubuntu versions, Ubuntu infrastructure, or official Xubuntu ISO files were affected. At the same time, existing Xubuntu users were completely unaffected, as the malware only targeted users who downloaded infected files from websites.

While waiting for the new website to be completed, users are recommended to safely download Xubuntu directly from the official address:
https://cdimage.ubuntu.com/xubuntu/releases/

Close
Category

System

Windows XP

Windows Server 2012

Windows 8

Windows 7

Windows 10

Wifi tips

Virus Removal - Spyware

Speed ​​up the computer

Server

Security solution

Mail Server

LAN - WAN

Ghost - Install Win

Fix computer error

Configure Router Switch

Computer wallpaper

Computer security

Mac OS X

Mac OS System software

Mac OS Security

Mac OS Office application

Mac OS Email Management

Mac OS Data - File

Mac hardware

Hardware

USB - Flash Drive

Speaker headset

Printer

PC hardware

Network equipment

Laptop hardware

Computer components

Advice Computer

Game

PC game

Online game

Mobile Game

Pokemon GO

information

Technology story

Technology comments

Quiz technology

New technology

British talent technology

Attack the network

Artificial intelligence

Technology

Smart watches

Raspberry Pi

Linux

Camera

Basic knowledge

Banking services

SEO tips

Science

Strange story

Space Science

Scientific invention

Science Story

Science photo

Science and technology

Medicine

Health Care

Fun science

Environment

Discover science

Discover nature

Archeology

Life

Travel Experience

Tips

Raise up child

Make up

Life skills

Home Care

Entertainment

DIY Handmade

Cuisine

Christmas

Application

Web Email

Website - Blog

Web browser

Support Download - Upload

Software conversion

Social Network

Simulator software

Online payment

Office information

Music Software

Map and Positioning

Installation - Uninstall

Graphic design

Free - Discount

Email reader

Edit video

Edit photo

Compress and Decompress

Chat, Text, Call

Archive - Share

Electric

Water heater

Washing machine

Television

Machine tool

Fridge

Fans

Air conditioning

Program

Unix and Linux

SQL Server

SQL

Python

Programming C

PHP

NodeJS

MongoDB

jQuery

JavaScript

HTTP

HTML

Git

Database

Data structure and algorithm

CSS and CSS3

C ++

C #

AngularJS

Mobile

Wallpapers and Ringtones

Tricks application

Take and process photos

Storage - Sync

Security and Virus Removal

Personalized

Online Social Network

Map

Manage and edit Video

Data

Chat - Call - Text

Browser and Add-on

Basic setup