SSHStalker Botnet Uses IRC C2 to Control Linux Systems via Legacy Kernel Exploits
ID: 57953725-2c8c-5d48-8f71-55b3219ba792
STIX ID: report--57953725-2c8c-5d48-8f71-55b3219ba792
Feed Name: The Hacker News
**SSHStalker** is an IRC-controlled Linux botnet and mass-compromise operation that uses an SSH scanner, a catalog of 16 legacy Linux kernel exploits (2009–2010 CVEs), and multiple payloads (Golang scanner, IRC/Perl bots, rootkits, log cleaners, and a keep‑alive component) to enroll vulnerable, often long-tail or forgotten servers into C2 channels and maintain dormant persistent access; attribution analysis shows operational overlap with the Outlaw actor and a staging repository containing additional offensive tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
