DShield Sensor Captures Self-Propagating SSH Worm Exploit Using Credential Stuffing and Multi-Stage Malware
ID: 9e5203f9-2b00-55a7-a91b-37404cf0c2d7
STIX ID: report--9e5203f9-2b00-55a7-a91b-37404cf0c2d7
Feed Name: cybersecurityNews.com
A self-propagating SSH worm exploits default or weak credentials on internet-exposed Linux/IoT devices (notably Raspberry Pi) to deploy a small bash payload that establishes persistence, eliminates competing malware, and connects infected hosts to an IRC-based botnet using cryptographically signed commands; the malware uses zmap and sshpass to scan hundreds of thousands of IPs and spreads rapidly via credential stuffing. The report is based on DShield honeypot captures identifying active exploitation and an initial compromised Raspberry Pi in Germany, and recommends disabling password-based SSH, removing default accounts, and deploying brute-force protections and network segmentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
