Researchers detailed two separate cryptomining botnets targeting large numbers of devices with stealth and persistence features. Palo Alto Networks Unit 42 reported that Eleethub used a malicious Perl shell script to infect Unix-like systems, connect them to IRC-based command-and-control servers, and deploy rootkit components including libprocesshider.so and a modified ps binary to hide mining activity. The malware mined cryptocurrency with XMRig and emech, and also included capabilities for UDP/TCP floods, HTTP attacks, and port scanning, indicating the operators were building a broader botnet that could support disruptive attacks beyond mining.
ESET separately uncovered and helped disrupt VictoryGate, a Monero-mining botnet active since at least 2019 that infected at least 35,000 devices, with more than 90% of victims located in Peru and broader concentration in Latin America. VictoryGate spread mainly through removable USB drives, used AutoIt-based droppers, process injection, and No-IP dynamic DNS subdomains for command and control, and typically monetized infections through XMRig mining. After ESET reported the malicious No-IP subdomains, the provider took them down, cutting off the botnet’s ability to issue new commands or fetch additional payloads, although already infected hosts could continue mining.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
ESET reported that the previously undocumented VictoryGate botnet had been active since at least May 2019. The botnet primarily spread via removable USB drives and monetized infections through Monero mining.
When Unit 42 discovered Eleethub, the botnet appeared to still be under development and only a small number of infected zombies were observed in its Miners channel. The infrastructure included eleethub[.]com and related IRC hosts tied to the campaign.
Unit 42 identified a new Perl shellbot campaign called Eleethub that infected Unix-like systems to mine cryptocurrency and potentially launch DDoS-style attacks. The malware used IRC-based command-and-control and rootkit components including libprocesshider.so and a modified ps binary to hide mining activity.
After ESET reported VictoryGate's malicious No-IP subdomains, No-IP took them down, disrupting the botnet's command-and-control. ESET also shared sinkhole logs with the Shadowserver Foundation to aid remediation, though infected hosts could continue mining.
ESET uncovered a previously undocumented botnet and named it VictoryGate. The researchers assessed it had infected at least 35,000 devices, with infections concentrated in Latin America and more than 90% in Peru.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
unit42.paloaltonetworks.com
Open sourcecriptonizando.com
Open sourcewelivesecurity.com
Open sourceeset.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.