logo

Battling Cryptojacking, Botnets, and IABs [Guest Diary], (Thu, Jan 15th)

ID: 1b45f5c0-282e-565e-84dc-f186df9ba291

STIX ID: report--1b45f5c0-282e-565e-84dc-f186df9ba291

Feed Name: SANS ISC Diary

Threat Score
60/100

Date Published: 2026-01-15

Date Updated: 2026-04-19

...
...

This guest diary analyzes DShield honeypot traffic showing a common attack chain: SSH password-spray -> automated system enumeration -> SSH persistence setup -> transfer and execution of a Go-based trojan/miner linked to botnet/cryptojacking operations. The author provides observed IPs and a malware hash, maps the attacker TTPs (attribution to an ‘Outlaw’ runbook is used as a threat model), and recommends mitigations including disabling password SSH auth, enforcing MFA, file integrity monitoring, log centralization, and proactive threat hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.