logo

RUBYCARP hackers linked to 10-year-old cryptomining botnet

ID: d9dc28f2-0795-55ec-a720-9e120ca738fc

STIX ID: report--d9dc28f2-0795-55ec-a720-9e120ca738fc

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-04-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Sysdig researchers uncovered RUBYCARP, a long-running Romanian botnet operating via IRC with a Perl-based shellbot and over 600 compromised servers; the group exploits known vulnerabilities (notably CVE-2021-3129), performs SSH and WordPress credential brute-forcing, rotates infrastructure to evade detection, and monetizes access through crypto-mining (NanoMiner, XMrig, C2Bash), phishing, fraud, and DDoS.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.