logo

Outlaw Botnet Exploits Weak SSH to Hijack Linux Systems for Crypto Mining

ID: 27f0b20c-0bc7-5a27-9ea7-a6da5501c64c

STIX ID: report--27f0b20c-0bc7-5a27-9ea7-a6da5501c64c

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2025-05-01

Date Updated: 2026-04-22

Author: Ddos

...
...

Kaspersky observed an active Outlaw (Dota) Linux-focused botnet campaign that compromises systems via weak/default SSH credentials, deploys an obfuscated Perl IRC backdoor and a UPX-packed XMRig CPU miner, removes competing miners, persists via altered SSH keys, and hides C2 and mining traffic over Tor; infections spiked across multiple countries in March 2025 and defenders are advised to harden SSH and apply brute-force protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.