SSHStalker is a previously undocumented Linux botnet focused on mass compromise of internet-exposed Linux servers through SSH scanning and brute-force authentication attempts. The operation uses an automated intrusion pipeline that rapidly stages tooling on newly compromised hosts, installs build dependencies when needed, and compiles multiple payloads directly on victim systems. Its command-and-control architecture relies on IRC, with multiple bot variants and redundant channels or servers to improve resilience. The botnet’s tradecraft emphasizes scale, persistence, and operational durability rather than immediate disruptive effects. It establishes recurring persistence through scheduled relaunch mechanisms and includes watchdog logic to restore bot processes if they are terminated. Observed tooling also includes log-cleaning components, rootkit-like artifacts, and execution from volatile or memory-backed locations to reduce forensic visibility. Researchers characterized this pattern as dormant persistence: maintaining long-term access and bot enrollment without immediately deploying overt impact operations during the observation period. SSHStalker’s toolkit includes legacy Linux privilege-escalation exploits primarily targeting outdated 2.6.x kernel generations, especially vulnerabilities from the 2009–2010 period. This suggests an opportunistic focus on neglected or long-tail systems rather than fully maintained infrastructure. The broader toolset includes IRC bot components associated with Tsunami and Keiten, Perl and C-based payloads, and additional reconnaissance capability aimed at harvesting exposed cloud credentials from web content. Cryptomining and DDoS-capable components were present in the ecosystem, indicating the operator retains monetization and attack options even when those functions were not actively observed. The operation appears to have heavily affected cloud-hosted Linux servers, with notable concentration in Oracle Cloud infrastructure across multiple regions. Its tactics and tooling resemble Outlaw or Maxlas-style Linux botnet activity, but no definitive attribution to those groups is established. Romanian-language artifacts and slang provide the strongest available clue regarding likely operator origin, but attribution remains unconfirmed. Overall, SSHStalker fits a mid-tier Linux botnet actor profile using old but reliable techniques—SSH brute force, multi-stage payload deployment, cron-based persistence, privilege escalation against legacy kernels, and IRC coordination—to build and retain a large pool of compromised systems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A newly identified Linux botnet operation infecting internet-facing Linux servers at scale via mass SSH scanning and brute-force, then deploying an IRC-based bot toolkit with cron-based persistence. Notably appears to prioritize dormant/quiet long-term access (staging/testing/future use) rather than immediate DDoS or cryptomining.
Previously undocumented Linux botnet operation using mass SSH scanning/brute-force for initial access, staging/compiling multiple IRC bot variants on-host, enrolling victims into IRC-based C2 (multi-server/channel redundancy), and maintaining persistence via per-minute cron watchdog. Tooling includes log cleaners (utmp/wtmp/lastlog tampering), rootkit-class artifacts, legacy Linux 2.6.x privilege-escalation exploits (2009–2010 CVEs), and optional monetization via cryptomining; also includes web scanning aimed at harvesting exposed AWS credentials.
Previously undocumented Linux botnet operation observed via SSH honeypot activity; described as blending legacy IRC botnet tactics with modern mass-compromise behavior.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.