Back to the Future: SSHStalker Botnet Revives 2009 Tactics to Hijack Linux Servers
ID: 15b134cf-32a2-54ac-bf2f-8cc286d8c658
STIX ID: report--15b134cf-32a2-54ac-bf2f-8cc286d8c658
Feed Name: securityonline.info
Threat Score
Flare researchers discovered SSHStalker, a Linux botnet that pairs a custom Go SSH scanner with rapid staging to brute-force weak SSH credentials and deploy multiple backdoors (legacy C bots, Perl scripts, known families like Tsunami and Keiten), using IRC for C2 and cron/watchdog persistence; the operator is assessed as mid-tier and focused on large-scale, resilient mass compromise rather than novel exploits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
