Maxlas is a Linux-focused botnet operator name associated with mass SSH compromise activity and tradecraft overlapping the broader Outlaw/Maxlas-style ecosystem, though definitive attribution to Outlaw is unconfirmed. The operation linked to this name has been observed using automated SSH scanning and brute-force style access acquisition, followed by rapid staging on compromised hosts, installation of build tooling, on-host compilation of multiple C-based payloads, and enrollment of victims into resilient IRC-based command-and-control infrastructure. The tooling emphasizes scale, redundancy, and durability rather than stealth. Observed post-compromise activity includes deployment of multiple IRC bot variants written in C and Perl, use of multi-server and multi-channel IRC redundancy, randomized client identities, and persistence through cron- or service-based relaunch mechanisms. The operator has used watchdog logic to restart bots quickly if terminated and has shown a preference for memory-backed execution locations to reduce disk artifacts. Defense-evasion behavior includes tampering with login and system accounting records, while privilege-oriented tooling includes backdoor components intended to execute with elevated rights. The toolset also contains numerous legacy Linux kernel exploit artifacts targeting older 2.6.x-era systems, indicating opportunistic post-exploitation and privilege-escalation capability against long-tail vulnerable hosts. Additional associated capabilities include distributed denial-of-service functionality in IRC bot components, rootkit-class artifacts, cryptomining-related tooling, and a separate web reconnaissance capability designed to scan websites at scale for exposed cloud credentials. Romanian-language and nickname signals, along with ecosystem overlap in tooling and playbooks, have led to comparisons with Romanian-linked Outlaw/Maxlas activity, but high-confidence attribution beyond that overlap is not established. Overall, Maxlas is best characterized as a financially motivated Linux botnet actor focused on broad opportunistic compromise, persistence, resource hijacking, and follow-on abuse of compromised infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.