logo

Mirai-based NoaBot Botnet Targeting Linux Systems with Cryptominer

ID: 99ad7f63-bf01-5184-9fe1-2caa36585645

STIX ID: report--99ad7f63-bf01-5184-9fe1-2caa36585645

Feed Name: HackRead

Threat Score
70/100

Date Published: 2024-01-11

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Akamai researchers uncovered NoaBot, a Mirai-derived botnet active since January 2023 that targets Linux servers by brute-forcing weak SSH credentials to install a modified XMRig cryptominer and deliver the P2PInfect worm; the malware is statically compiled with UClibc, uses obfuscated strings and randomized runtime folders for stealth, and has infected over 800 unique IPs worldwide. The report notes technical indicators and behaviors (custom SSH scanner, persistence via SSH authorized keys, private mining pool) and recommends hardening measures—patching, strong passwords, MFA, and monitoring—to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.