logo

From SSH bruteforce to cryptojacking (Campaign)

ID: a0c2e107-c1a7-58e1-9c1e-1f924cc32567

STIX ID: report--a0c2e107-c1a7-58e1-9c1e-1f924cc32567

Feed Name: Wiz Cloud Threat Landscape

Threat Score
60/100

Date Published: 2023-09-08

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers observed an active campaign brute-forcing misconfigured Linux SSH servers to deploy a malicious shell script called `hoze`, which downloads `xrx.tar` (containing scripts that disable security software and set executables) and `config.json` for XMRig crypto-mining. A malicious IP and a public SSH key tied to a previous CoinMiner operation link this activity to ongoing cryptojacking aimed at hijacking servers for mining.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.