RUBYCARP hackers linked to 10-year-old cryptomining botnet
ID: d9dc28f2-0795-55ec-a720-9e120ca738fc
STIX ID: report--d9dc28f2-0795-55ec-a720-9e120ca738fc
Feed Name: Bleeping Computer
Threat Score
Sysdig researchers uncovered RUBYCARP, a long-running Romanian botnet operating via IRC with a Perl-based shellbot and over 600 compromised servers; the group exploits known vulnerabilities (notably CVE-2021-3129), performs SSH and WordPress credential brute-forcing, rotates infrastructure to evade detection, and monetizes access through crypto-mining (NanoMiner, XMrig, C2Bash), phishing, fraud, and DDoS.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
