logo

Threat Actors Installing Linux Backdoor Accounts

ID: 318e51cd-78f3-503e-b6cd-69ce42b2f47a

STIX ID: report--318e51cd-78f3-503e-b6cd-69ce42b2f47a

Feed Name: ASEC

Threat Score
70/100

Date Published: 2024-02-02

Date Updated: 2026-04-26

Author: Sanseo

...
...

The AhnLab ASEC honeypot report details ongoing campaigns targeting poorly managed Linux SSH servers using IP scanning and brute-force/dictionary logins to add backdoor accounts, change root passwords, or register attacker SSH keys for persistence. The report includes concrete command examples, lists of attacker IPs and credentials, and documents follow-on payloads such as XMRig coinminers and DDoS bots, concluding with mitigation recommendations (strong passwords, key-based auth, disable root SSH, firewalling, patching).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.