SSHStalker Botnet Uses IRC C2 to Control Linux Systems via Legacy Kernel Exploits
Details of a new botnet operation known as SSHStalker, which uses the Internet Relay Chat (IRC) communication protocol for command-and-control (C2) purposes, have been made public by cybersecurity researchers.
The arsenal combines legacy-era Linux exploitation with stealth helpers: "The actor maintains a sizable back-catalog of Linux 2.6.x-era exploits (2009–2010 CVEs) in addition to log cleaners (utmp/wtmp/lastlog tampering) and rootkit-class artifacts," cybersecurity firm Flare stated. "Remaining effective against long-tail legacy environments and 'forgotten' infrastructure, these are low value against newer stacks.
An SSH scanner and other easily accessible scanners are used by SSHStalker, an automated mass-compromise operation that combines IRC botnet mechanics with the ability ...

