logo

Case Study: Distribution of a CoinMiner Targeting Linux SSH Servers via Malware Distribution via Network Transmission

ID: 68bcd90d-0378-5279-9850-0483881c952f

STIX ID: report--68bcd90d-0378-5279-9850-0483881c952f

Feed Name: ASEC

Threat Score
70/100

Date Published: 2026-07-11

Date Updated: 2026-07-15

Author: ATCP

...
...

**Executive Summary:** ASEC observed an ongoing campaign targeting poorly managed Linux servers that uses SSH scanning and brute-force to deliver Go-based propagation malware, a custom XMRig CoinMiner (installed with persistence via systemd/cron and watchdog mechanisms), ShellBot (Perl DDoS bot), and command-obfuscation tools (Shc, XHide). The report includes malware behavioral details, installation and propagation commands, and multiple IoCs (URLs, IPs, FQDNs, MD5s) to aid detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.