New Linux botnet SSHStalker uses old-school IRC for C2 comms
ID: 4bdde82c-b475-5b7d-a531-e369bfaf10b3
STIX ID: report--4bdde82c-b475-5b7d-a531-e369bfaf10b3
Feed Name: Bleeping Computer
SSHStalker is a newly documented Linux botnet that relies on old-school IRC for C2 and worm-like propagation via automated SSH scanning and brute-force; compromised hosts compile and run C-based IRC bots, fetch orchestration archives, and maintain persistence through cron jobs that run every 60 seconds. Researchers observed nearly 7,000 scan results focused on cloud infrastructure, noted use of a back-catalog of 16 legacy Linux CVE exploits for privilege escalation, and identified monetization capabilities including cryptomining and AWS key harvesting; mitigations recommended include disabling SSH password auth, removing compilers from production images, monitoring for short-interval cron jobs and IRC outbound connections, and enforcing egress filtering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
