Legacy IRC Botnet Leverages Automated SSH Exploit Pipeline to Mass-Enroll Linux Hosts
ID: dedb706f-1a9e-5e48-bb23-a3b47ca081e7
STIX ID: report--dedb706f-1a9e-5e48-bb23-a3b47ca081e7
Feed Name: GBHackers
SSHStalker is an active Linux botnet campaign observed via SSH honeypots that combines Golang-based scanning, on-victim compilation of C binaries, and IRC-based command-and-control to build a resilient botnet; it employs a cron “watchdog” that recompiles and relaunches the malware every 60 seconds, has exploited legacy Linux kernel vulnerabilities to compromise long-tail cloud and IoT systems (approximately 7,000 IPs noted, concentrated in cloud providers like Oracle Cloud), and is used for Ethereum Classic mining and harvesting AWS credentials. The report provides IOCs (hashes, IPs, domains), detection guidance (monitor gcc/make in /tmp or /dev/shm, block outbound IRC, watch for minute-level cron jobs), and notes a likely Romanian-language toolset link but no definitive attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
