logo

Back to the Future: SSHStalker Botnet Revives 2009 Tactics to Hijack Linux Servers

ID: 15b134cf-32a2-54ac-bf2f-8cc286d8c658

STIX ID: report--15b134cf-32a2-54ac-bf2f-8cc286d8c658

Feed Name: securityonline.info

Threat Score
65/100

Date Published: 2026-02-13

Date Updated: 2026-04-23

Author: Ddos

...
...

Flare researchers discovered SSHStalker, a Linux botnet that pairs a custom Go SSH scanner with rapid staging to brute-force weak SSH credentials and deploy multiple backdoors (legacy C bots, Perl scripts, known families like Tsunami and Keiten), using IRC for C2 and cron/watchdog persistence; the operator is assessed as mid-tier and focused on large-scale, resilient mass compromise rather than novel exploits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.