10-Year-Old 'RUBYCARP' Romanian Hacker Group Surfaces with Botnet
ID: d1c26109-4ccb-5831-b36d-f72480e1fa4b
STIX ID: report--d1c26109-4ccb-5831-b36d-f72480e1fa4b
Feed Name: The Hacker News
Threat Score
RUBYCARP is a long-running, financially motivated cybercriminal group (likely Romanian) operating a botnet of over 600 compromised hosts to conduct crypto-mining, DDoS and phishing. The group deploys ShellBot (PerlBot), leverages public exploits (e.g., Laravel CVE-2021-3129), brute-force/credential reuse against WordPress, and coordinates via public/private IRC (notably chat.juicessh.pro and an Undernet channel), indicating an established, multifaceted criminal operation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
