logo

Unpacking Diicot - Evolving Campaign Targeting Linux Environments

ID: c8d2b70e-7856-5632-be37-8156c9549fe5

STIX ID: report--c8d2b70e-7856-5632-be37-8156c9549fe5

Feed Name: Wiz Blog

Threat Score
75/100

Date Published: 2024-12-17

Date Updated: 2026-05-01

...
...

Wiz Research discovered an active Linux-targeting malware campaign attributed to the Romanian-speaking Diicot (Mexals) group that leverages SSH brute-force, cloud-aware Go binaries with modified UPX packing, reverse shells, cron-based persistence, and cryptomining (XMRig and Zephyr). The campaign uses multiple payloads (Update, cache, .bisis, abc123), evolving infrastructure and C2s, and has been observed across cloud providers with documented IOCs including file hashes, domains, IPs, and mining pool credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.