logo

NoaBot: Latest Mirai-Based Botnet Targeting SSH Servers for Crypto Mining

ID: 09311b59-6462-538b-8dc3-26f1554658bd

STIX ID: report--09311b59-6462-538b-8dc3-26f1554658bd

Feed Name: The Hacker News

Threat Score
68/100

Date Published: 2024-01-10

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

Akamai researchers disclosed NoaBot, a Mirai-derived wormable botnet used since early 2023 for a global cryptomining campaign. NoaBot brute-forces SSH via dictionary attacks to insert SSH public keys and enable lateral movement, can download/execute additional binaries, and deploys an obfuscated variant of the XMRig miner that hides its pool/wallet; 849 victim IPs were observed with a notable concentration in China. The campaign shows links to other IoT/router-targeting malware (P2PInfect) and the report recommends restricting internet-facing SSH and using strong passwords.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.