NoaBot: Latest Mirai-Based Botnet Targeting SSH Servers for Crypto Mining
ID: 09311b59-6462-538b-8dc3-26f1554658bd
STIX ID: report--09311b59-6462-538b-8dc3-26f1554658bd
Feed Name: The Hacker News
Akamai researchers disclosed NoaBot, a Mirai-derived wormable botnet used since early 2023 for a global cryptomining campaign. NoaBot brute-forces SSH via dictionary attacks to insert SSH public keys and enable lateral movement, can download/execute additional binaries, and deploys an obfuscated variant of the XMRig miner that hides its pool/wallet; 849 victim IPs were observed with a notable concentration in China. The campaign shows links to other IoT/router-targeting malware (P2PInfect) and the report recommends restricting internet-facing SSH and using strong passwords.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
