Dramatic server room scene illustrating the SSHStalker Linux botnet infecting thousands of vulnerable servers via SSH exploits.
Dramatic server room scene illustrating the SSHStalker Linux botnet infecting thousands of vulnerable servers via SSH exploits.
AI에 의해 생성된 이미지

Researchers discover SSHStalker botnet infecting Linux servers

AI에 의해 생성된 이미지

Flare researchers have identified a new Linux botnet called SSHStalker that has compromised around 7,000 systems using outdated exploits and SSH scanning. The botnet employs IRC for command-and-control while maintaining dormant persistence without immediate malicious activities like DDoS or cryptomining. It targets legacy Linux kernels, highlighting risks in neglected infrastructure.

In early 2026, Flare researchers deployed an SSH honeypot with weak credentials and observed unusual intrusions over two months. After reviewing threat intelligence databases, vendor reports, and malware repositories, they confirmed the activity as previously undocumented and named it SSHStalker. The botnet combines 2009-era IRC botnet tactics with automated mass-compromise techniques, infecting systems via SSH brute-force attacks and scanning.

SSHStalker breaks into Linux servers by guessing weak or reused passwords, then deploys a multi-stage payload. Attackers drop a Golang binary disguised as "nmap" to probe port 22 for new targets, download GCC to compile C files on the host, and unpack archives like GS and bootbou.tgz containing IRC bots written in C and Perl, along with known malware families such as Tsunami and Keiten. The toolkit includes log cleaners that target shell history and records like utmp, wtmp, and lastlog, as well as rootkit-like artifacts and exploits for Linux 2.6.x kernels from 2009-2010 CVEs.

Once installed, the botnet establishes persistence through cron jobs that run every minute to restart processes if disrupted, often restoring control within 60 seconds. Analysis of staging servers revealed nearly 7,000 freshly compromised systems in January 2026, primarily cloud servers linked to Oracle Cloud infrastructure across global regions.

"We’ve designated this operation 'SSHStalker' due to its distinctive behavior: the botnet maintained persistent access without executing any observable impact operations," the Flare report states. This "dormant persistence" suggests staging, testing, or retention for future use, with bots connecting to IRC channels on a legitimate public network to blend into normal traffic.

While tactics resemble Outlaw or Maxlas-style botnets, no direct attribution exists, though Romanian-language artifacts in configs and channels indicate a possible origin. The operation prioritizes scale and reliability over stealth, affecting 1-3% of internet-facing Linux servers, particularly in legacy environments like outdated VPS or embedded devices.

Flare provides indicators of compromise and mitigation advice, including removing cron entries, deleting kits from /dev/shm, disabling SSH password authentication, and monitoring for unexpected compilations or IRC connections.

사람들이 말하는 것

Cybersecurity professionals and outlets on X are reacting to the SSHStalker botnet, which infects ~7,000 legacy Linux servers using old exploits, SSH brute-forcing, and IRC for C2. Discussions highlight the dangers of unpatched infrastructure, the effectiveness of outdated techniques, and urge immediate patching and SSH hardening. Sentiments are mostly neutral with cautionary tones from analysts and journalists.

관련 기사

Illustration depicting the Linux CopyFail vulnerability enabling root access exploits alongside Ubuntu's DDoS-induced outage.
AI에 의해 생성된 이미지

Linux CopyFail exploit threatens root access amid Ubuntu outage

AI에 의해 보고됨 AI에 의해 생성된 이미지

A critical Linux vulnerability known as CopyFail, tracked as CVE-2026-31431, allows attackers to gain root access on systems running kernels since 2017. Publicly released exploit code has heightened risks for data centers and personal devices. Ubuntu's infrastructure has been offline for over a day due to a DDoS attack, hampering security communications.

Developer platform Socket has identified a malware known as TrapDoor that is targeting crypto and AI developers.

AI에 의해 보고됨

Researchers have uncovered a large-scale compromise of Fortinet firewalls that exposed plaintext credentials for nearly 74,000 devices across 194 countries. The breach affects organizations including Oracle, Chevron, Lenovo, FedEx, and Fortinet itself, along with a NATO defense contractor.

이 웹사이트는 쿠키를 사용합니다

사이트를 개선하기 위해 분석을 위한 쿠키를 사용합니다. 자세한 내용은 개인정보 보호 정책을 읽으세요.
거부