Statistics Report of Malware Targeting Linux SSH Servers in Q3 2025
ID: 18afc7f3-2b70-5f1b-813b-edd5b7590be7
STIX ID: report--18afc7f3-2b70-5f1b-813b-edd5b7590be7
Feed Name: ASEC
Threat Score
AhnLab ASEC’s Q3 2025 honeypot analysis documents widespread brute-force attacks against Linux SSH servers that deliver a variety of malware (DDoS bots such as Mirai/Gafgyt/Tsunami, coin miners like XMRig/Prometei, and bots built from HaiBot source code). The report describes attacker commands and build/download chains, C2 communication patterns, includes observed MD5 hashes and URLs for payloads, and highlights active exploitation and IoCs for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
