logo

‘Yet another Mirai-based botnet’ is spreading an illicit cryptominer

ID: 3a99c29a-f046-5b87-9deb-5eff94894654

STIX ID: report--3a99c29a-f046-5b87-9deb-5eff94894654

Feed Name: The Record from Recorded Future News

Threat Score
65/100

Date Published: 2024-01-10

Date Updated: 2026-05-01

...
...

NoaBot is a Mirai-derived botnet campaign observed for about a year that spreads via Linux SSH and installs a modified XMRig cryptominer. Akamai researchers highlight substantial code obfuscation and customizations indicating operational security and capability, possible ties to the P2PInfect worm, and actor behaviors that complicate attribution despite juvenile in-jokes embedded in binaries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.