Unpacking Diicot - Evolving Campaign Targeting Linux Environments
ID: c8d2b70e-7856-5632-be37-8156c9549fe5
STIX ID: report--c8d2b70e-7856-5632-be37-8156c9549fe5
Feed Name: Wiz Blog
Wiz Research discovered an active Linux-targeting malware campaign attributed to the Romanian-speaking Diicot (Mexals) group that leverages SSH brute-force, cloud-aware Go binaries with modified UPX packing, reverse shells, cron-based persistence, and cryptomining (XMRig and Zephyr). The campaign uses multiple payloads (Update, cache, .bisis, abc123), evolving infrastructure and C2s, and has been observed across cloud providers with documented IOCs including file hashes, domains, IPs, and mining pool credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
