logo

Legacy IRC Botnet Campaign Uses Automated SSH Compromise Pipeline to Enroll Linux Hosts at Scale

ID: 72148bad-f0dd-50a3-9b9d-e53a1638d0b6

STIX ID: report--72148bad-f0dd-50a3-9b9d-e53a1638d0b6

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-02-11

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

SSHStalker is a newly identified Linux botnet that automates SSH credential guessing to compromise hosts, deploys IRC-based command-and-control via compiled C and Perl bots and helper tools, and maintains resilient persistence using a one-minute cron watchdog that can restore control within about 60 seconds; researchers observed staging data referencing nearly 7,000 SSH scan results (including cloud ranges) and recommend disabling SSH password authentication, enforcing key-based access and rate-limiting, removing the cron entry and kit directories (often in /dev/shm), and monitoring for on-host compilation and IRC egress.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.