Weaponizing gcc: Inside the Stealthy ‘Hex’ Botnet’s On-Host Compilation Strategy
ID: 8386a329-5279-5b48-b352-36fefb225c49
STIX ID: report--8386a329-5279-5b48-b352-36fefb225c49
Feed Name: securityonline.info
Hunt Intelligence uncovered a 15-node 'Hex' botnet that pushes source code to infected Linux hosts and compiles a DDoS client on-host using gcc to evade binary detection; propagation is automated via a Python deployment script (ohhhh.py) that abuses stolen SSH credentials to open hundreds of concurrent sessions, and the infrastructure leverages Iranian hosting and Finnish KCP exit nodes for C2 and censorship-bypass—defenders are advised to harden SSH, monitor compiler usage, and look for indicators like the 'hex' binary and config-client.yaml.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
