New Stealthy Linux Malware Combines Mirai-Derived DDoS Botnet and Fileless Cryptominer
ID: e918a9f1-0844-5f44-900f-0a90b9714968
STIX ID: report--e918a9f1-0844-5f44-900f-0a90b9714968
Feed Name: cybersecurityNews.com
Security researchers observed a sophisticated Linux malware campaign named V3G4 that merges Mirai-style DDoS botnet capabilities with a fileless XMRig Monero miner. The multi-stage infection begins with a Universal Bot Downloader shell script that detects CPU architecture and fetches tailored payloads (supporting x86_64, ARM, MIPS variants) from attacker servers; the UPX-packed binary performs environment reconnaissance, masquerades as systemd-logind, conducts high-speed SSH/port-22 scanning and DNS-resilient C2 resolution, and retrieves miner configuration dynamically from C2 domains/IPs to run a stealthy, in-memory cryptominer while also enabling DDoS operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
