Details of a new botnet operation known as SSHStalker, which uses the Internet Relay Chat (IRC) communication protocol for command-and-control (C2) purposes, have been made public by cybersecurity researchers.
The arsenal combines legacy-era Linux exploitation with stealth helpers: “The actor maintains a sizable back-catalog of Linux 2.6.x-era exploits (2009–2010 CVEs) in addition to log cleaners (utmp/wtmp/lastlog tampering) and rootkit-class artifacts,” cybersecurity firm Flare stated. “Remaining effective against long-tail legacy environments and ‘forgotten’ infrastructure, these are low value against newer stacks.
An SSH scanner and other easily accessible scanners are used by SSHStalker, an automated mass-compromise operation that combines IRC botnet mechanics with the ability to co-opt vulnerable systems into a network and enroll them in IRC channels.
But in contrast to other operations that usually use these botnets for opportunistic activities like bitcoin mining read more about SSHStalker Botnet Uses IRC C2 to Control Linux Systems via Legacy Kernel Exploits.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
