logo

DShield Sensor Captures Self-Propagating SSH Worm Exploit Using Credential Stuffing and Multi-Stage Malware

ID: 9e5203f9-2b00-55a7-a91b-37404cf0c2d7

STIX ID: report--9e5203f9-2b00-55a7-a91b-37404cf0c2d7

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-12

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A self-propagating SSH worm exploits default or weak credentials on internet-exposed Linux/IoT devices (notably Raspberry Pi) to deploy a small bash payload that establishes persistence, eliminates competing malware, and connects infected hosts to an IRC-based botnet using cryptographically signed commands; the malware uses zmap and sshpass to scan hundreds of thousands of IPs and spreads rapidly via credential stuffing. The report is based on DShield honeypot captures identifying active exploitation and an initial compromised Raspberry Pi in Germany, and recommends disabling password-based SSH, removing default accounts, and deploying brute-force protections and network segmentation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.