SSH Worm Exploit Detected by DShield Sensor Using Credential Stuffing and Multi-Stage Malware
ID: d4d8b8cd-5763-5016-a52d-a713a9f1385e
STIX ID: report--d4d8b8cd-5763-5016-a52d-a713a9f1385e
Feed Name: GBHackers
A DShield honeypot captured a rapid compromise where an SSH worm brute‑forced default Raspberry Pi credentials (pi/raspberry*) to upload a 4.7 KB bash script that established persistence, removed competing malware, and enrolled the host in an IRC-based botnet (#biret). The worm installed zmap and sshpass, scanned ~100,000 IPs, attempted two credential pairs to propagate, validated commands with an embedded RSA key, and is capable of deploying additional payloads (e.g., cryptominers) by command; the report highlights ongoing risk from exposed SSH and default IoT credentials and recommends SSH hardening, removing default users, and network segregation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
