Bad news for one of the most popular Linux distros. The people behind Linux Mint announced on their official blog that both the main page and the ISO images belonging to the version 17.3 Cinnamon of the operating system were compromised. Anyone who downloaded Mint during February 20 probably received an image with a backdoor integrated, and although the number of users is small, it is recommended to carry out some checks.

Linux Mint website hacked and backdoor planted in ISO images
Linux Mint

If we go by the ranking of the DistroWatch portal, Linux Mint is the most popular distro at the moment, and it has a considerable lead over its direct competitors (Debian and Ubuntu). Many users disenchanted with Ubuntu (for different reasons) found a new home in Linux Mint, more in line with what the old pre-Unity Ubuntu was, and there is no doubt that its developers are doing a good job. Unfortunately, popularity can turn any project into a tempting target for an indefinite number of malicious elements looking to cause harm, and Linux Mint is no exception.

Linux Mint website hacked and backdoor planted in ISO images
It's a shame to see this distro in such a situation.

During yesterday, the official Linux Mint blog announced that its website and forums were attacked by hackers (via WordPress), who altered the download links for the ISO images of version 17.3 Cinnamon, redirecting all requests to similar images, but modified with a backdoor. The announcement explains that the affected images are only those downloaded through the main page, therefore, those who obtained their copies via a mirror or BitTorrent should be safe (the same extends to users of the MATE edition, and to those who obtained previous versions). All users who downloaded Mint Cinnamon ISO images on February 20 must compare the MD5 signature of their images with the original signatures:

  • 6e7f7e03500747c6c3bfece2c9c8394f linuxmint-17.3-cinnamon-32bit.iso
  • e71a2aad8b58605e906dbea444dc4983 linuxmint-17.3-cinnamon-64bit.iso
  • 30fef1aa1134c5f3778c77c4417f7238 linuxmint-17.3-cinnamon-nocodecs-32bit.iso
  • 3406350a87c201cdca0927b1bc7c2ccd linuxmint-17.3-cinnamon-nocodecs-64bit.iso
  • df38af96e99726bb0a1ef3e5cd47563d linuxmint-17.3-cinnamon-oem-64bit.iso

Needless to say, if the signatures are not identical, that means you have an infected copy.

At the same time, the people responsible for Linux Mint recommend verifying the path /var/lib/man.cy in recent Cinnamon installations, and if there is a file inside, it means you have the backdoor. What follows for both cases is inevitable: delete the compromised images, format any pendrive, destroy optical discs, and of course, purge the computer with the infected build. If a user accessed online services with an infected copy of Mint, it is also recommended to change the passwords of those services as soon as possible.

Official announcement: