logo

SSHStalker Botnet Uses IRC C2 to Control Linux Systems via Legacy Kernel Exploits

ID: 57953725-2c8c-5d48-8f71-55b3219ba792

STIX ID: report--57953725-2c8c-5d48-8f71-55b3219ba792

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-02-11

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**SSHStalker** is an IRC-controlled Linux botnet and mass-compromise operation that uses an SSH scanner, a catalog of 16 legacy Linux kernel exploits (2009–2010 CVEs), and multiple payloads (Golang scanner, IRC/Perl bots, rootkits, log cleaners, and a keep‑alive component) to enroll vulnerable, often long-tail or forgotten servers into C2 channels and maintain dormant persistent access; attribution analysis shows operational overlap with the Outlaw actor and a staging repository containing additional offensive tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.