Protect Gen V1 VM running ubuntu 18.04. threats from Drovorub.

sachin Chand 21 Reputation points
2020-08-30T08:20:08.95+00:00

have a Gen V1 VM running ubuntu 18.04. There is a request to enable UEFI boot to remediate threats from Drovorub. Is there a process of best practices to protect Azure VM on Linux from Drovorub?

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,479 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
{count} votes

Accepted answer
  1. prmanhas-MSFT 17,901 Reputation points Microsoft Employee
    2020-09-01T15:10:52.937+00:00

    @sachin Chand Apologies for the delay in response and all the inconvenience caused because of the issue.

    Drovorub is a malware framework consisting of several components, including a kernel rootkit, tools for file transfer and port forwarding, and a command-and-control (CC) server.

    Drovorub communicates with the CC server and hides its presence on the target system. It provides the attackers with file upload and download capabilities, as well as arbitrary command execution (with root privileges) and port or network traffic forwarding to other hosts on the network.

    As with other rootkits and backdoors, an attacker needs to first compromise the target system by an unrelated exploit, before Drovorub can be deployed.

    You can refer to this article which consist of generic steps to follow on the Linux System.

    This article contains security recommendations for Azure Virtual Machines. Follow these recommendations to help fulfill the security obligations described in our model for shared responsibility. The recommendations will also help you improve overall security for your web app solutions.

    Another approach is to use policies on virtual machines in Azure.You can refer to this,which is a general advisory from Microsoft side for securing your Virtual Machine which is applicable for all the vulnerabilities and malware in general.

    Hope it helps!!!

    Do let me know in case of any queries.

    Please 'Accept as answer' if it helped, so that it can help others in the community looking for help on similar topics

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful