logo

Gafgyt Botnet: Weak SSH Passwords Targeted For GPU Mining

ID: 3e4a348f-6fea-576e-890b-377df78d39bd

STIX ID: report--3e4a348f-6fea-576e-890b-377df78d39bd

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2024-08-27

Date Updated: 2026-04-22

Author: Wajahat Raja

...
...

A newly observed Gafgyt botnet variant is actively brute-forcing weak SSH credentials to compromise devices and cloud-native servers, deploying a GPU-enabled XMRig Monero miner that leverages –opencl and –cuda to use GPU/NVIDIA resources. The variant includes a worming/scanning module (ID-musl-x86), terminates competing malware, uses Tor to hide activity, and is linked to the Keksec actor; researchers warn this represents an evolution toward targeting high-CPU/GPU cloud environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.