Statistical Report on Malware Targeting Linux SSH Servers in the Second Quarter of 2026
ID: 038ab2d7-245e-55a2-b13f-5b0538e01ce9
STIX ID: report--038ab2d7-245e-55a2-b13f-5b0538e01ce9
Feed Name: ASEC
In Q2 2026 AhnLab ASEC observed widespread brute-force and credential-based attacks against poorly managed Linux SSH servers that led to deployment of multiple malware families including XMRig (crypto-miner), Go-based propagation malware, ShellBot, and MIG LogCleaner. The report includes MD5 hashes, malicious URLs, IP addresses and domain names used by the attackers, describes downloader and obfuscation techniques (Shc, XHide), and recommends stronger passwords, timely patching, and access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
