Legacy IRC Botnet Campaign Uses Automated SSH Compromise Pipeline to Enroll Linux Hosts at Scale
ID: 72148bad-f0dd-50a3-9b9d-e53a1638d0b6
STIX ID: report--72148bad-f0dd-50a3-9b9d-e53a1638d0b6
Feed Name: cybersecurityNews.com
SSHStalker is a newly identified Linux botnet that automates SSH credential guessing to compromise hosts, deploys IRC-based command-and-control via compiled C and Perl bots and helper tools, and maintains resilient persistence using a one-minute cron watchdog that can restore control within about 60 seconds; researchers observed staging data referencing nearly 7,000 SSH scan results (including cloud ranges) and recommend disabling SSH password authentication, enforcing key-based access and rate-limiting, removing the cron entry and kit directories (often in /dev/shm), and monitoring for on-host compilation and IRC egress.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
