Mirai-based NoaBot Botnet Targeting Linux Systems with Cryptominer
ID: 99ad7f63-bf01-5184-9fe1-2caa36585645
STIX ID: report--99ad7f63-bf01-5184-9fe1-2caa36585645
Feed Name: HackRead
Akamai researchers uncovered NoaBot, a Mirai-derived botnet active since January 2023 that targets Linux servers by brute-forcing weak SSH credentials to install a modified XMRig cryptominer and deliver the P2PInfect worm; the malware is statically compiled with UClibc, uses obfuscated strings and randomized runtime folders for stealth, and has infected over 800 unique IPs worldwide. The report notes technical indicators and behaviors (custom SSH scanner, persistence via SSH authorized keys, private mining pool) and recommends hardening measures—patching, strong passwords, MFA, and monitoring—to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
