Case Study: Distribution of a CoinMiner Targeting Linux SSH Servers via Malware Distribution via Network Transmission
ID: 68bcd90d-0378-5279-9850-0483881c952f
STIX ID: report--68bcd90d-0378-5279-9850-0483881c952f
Feed Name: ASEC
**Executive Summary:** ASEC observed an ongoing campaign targeting poorly managed Linux servers that uses SSH scanning and brute-force to deliver Go-based propagation malware, a custom XMRig CoinMiner (installed with persistence via systemd/cron and watchdog mechanisms), ShellBot (Perl DDoS bot), and command-obfuscation tools (Shc, XHide). The report includes malware behavioral details, installation and propagation commands, and multiple IoCs (URLs, IPs, FQDNs, MD5s) to aid detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
