logo

SSHStalker botnet targets Linux servers with legacy exploits and SSH scanning

ID: 82d2eeb4-d2d3-5044-af80-c6f27aaf16e4

STIX ID: report--82d2eeb4-d2d3-5044-af80-c6f27aaf16e4

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-02-11

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Flare researchers have documented SSHStalker, a Linux botnet that used mass SSH scanning, brute-force credentials and a toolkit of 2009–2010-era Linux 2.6.x kernel exploits to compromise ~7,000 mostly cloud servers; the operation installs IRC-based bots, uses cron jobs for noisy but effective persistence, and appears to favor quiet long-term access rather than immediate DDoS or cryptomining, with investigators providing IoCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.