logo

Betting on Bots: Investigating Linux malware, crypto mining, and gambling API abuse

ID: ed5b91bf-6269-5097-bfb9-35f2fa5c2911

STIX ID: report--ed5b91bf-6269-5097-bfb9-35f2fa5c2911

Feed Name: Elastic Security Labs

Threat Score
70/100

Date Published: 2024-09-27

Date Updated: 2026-04-27

...
...

Elastic Security Labs analyzed an active Linux malware campaign (REF6138) that exploited Apache2 servers to deploy multiple toolsets — including KAIJI (DDoS), RUDEDEVIL/LUCIFER (cryptominer), custom binaries, and GSOCKET for covert persistence — and provided detailed behavioral analysis, C2/TTP descriptions, YARA and hunting rules, and a comprehensive set of IOCs (domains, IPs, hashes, and wallet addresses) to support detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.