Gafgyt Botnet: Weak SSH Passwords Targeted For GPU Mining
ID: 3e4a348f-6fea-576e-890b-377df78d39bd
STIX ID: report--3e4a348f-6fea-576e-890b-377df78d39bd
Feed Name: Security Boulevard
A newly observed Gafgyt botnet variant is actively brute-forcing weak SSH credentials to compromise devices and cloud-native servers, deploying a GPU-enabled XMRig Monero miner that leverages –opencl and –cuda to use GPU/NVIDIA resources. The variant includes a worming/scanning module (ID-musl-x86), terminates competing malware, uses Tor to hide activity, and is linked to the Keksec actor; researchers warn this represents an evolution toward targeting high-CPU/GPU cloud environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
