Betting on Bots: Investigating Linux malware, crypto mining, and gambling API abuse
ID: ed5b91bf-6269-5097-bfb9-35f2fa5c2911
STIX ID: report--ed5b91bf-6269-5097-bfb9-35f2fa5c2911
Feed Name: Elastic Security Labs
Threat Score
Elastic Security Labs analyzed an active Linux malware campaign (REF6138) that exploited Apache2 servers to deploy multiple toolsets — including KAIJI (DDoS), RUDEDEVIL/LUCIFER (cryptominer), custom binaries, and GSOCKET for covert persistence — and provided detailed behavioral analysis, C2/TTP descriptions, YARA and hunting rules, and a comprehensive set of IOCs (domains, IPs, hashes, and wallet addresses) to support detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
