logo

Outlaw Linux Malware: Persistent, Unsophisticated, and Surprisingly Effective

ID: 775299ab-4e93-5a15-988b-e7228d6d1bad

STIX ID: report--775299ab-4e93-5a15-988b-e7228d6d1bad

Feed Name: Elastic Security Labs

Threat Score
70/100

Date Published: 2025-04-01

Date Updated: 2026-04-27

...
...

This report analyzes OUTLAW, an actively observed, unsophisticated but persistent Linux coinminer/worm that spreads through SSH brute-force (BLITZ), maintains persistence via cron and SSH key manipulation, runs a modified XMRig miner, and provides IRC-based command-and-control (STEALTH SHELLBOT). The authors deploy a honeypot to capture operator behavior and provide a full attack-chain mapping to MITRE ATT&CK, YARA and detection rules, hunting queries, and IOCs to help defenders detect and mitigate infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.