Am I right in reading the Symantec C&C report and seeing that the servers were on Linux machines? Were the hiding the activity from themselves in case they were compromised? I assumed that they were infecting machines and using them as servers. Was there a linux vulnerability too?

