logo

Legacy IRC Botnet Leverages Automated SSH Exploit Pipeline to Mass-Enroll Linux Hosts

ID: dedb706f-1a9e-5e48-bb23-a3b47ca081e7

STIX ID: report--dedb706f-1a9e-5e48-bb23-a3b47ca081e7

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-02-11

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

SSHStalker is an active Linux botnet campaign observed via SSH honeypots that combines Golang-based scanning, on-victim compilation of C binaries, and IRC-based command-and-control to build a resilient botnet; it employs a cron “watchdog” that recompiles and relaunches the malware every 60 seconds, has exploited legacy Linux kernel vulnerabilities to compromise long-tail cloud and IoT systems (approximately 7,000 IPs noted, concentrated in cloud providers like Oracle Cloud), and is used for Ethereum Classic mining and harvesting AWS credentials. The report provides IOCs (hashes, IPs, domains), detection guidance (monitor gcc/make in /tmp or /dev/shm, block outbound IRC, watch for minute-level cron jobs), and notes a likely Romanian-language toolset link but no definitive attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.