New PumaBot Botnet Targets Linux IoT Devices to Steal SSH Credentials and Mine Crypto
PumaBot is a new botnet that targets Internet of Things (IoT) devices that are embedded with Linux.
The botnet, which was created in Go, is intended to use brute-force assaults on SSH instances in order to grow in size and scale and spread more malware to the compromised servers.
In a study provided to The Hacker News, Darktrace stated that instead of searching the internet, the virus obtains a list of targets from a command-and-control (C2) server and tries to brute force SSH passwords. Once it has access, it uses system service files to create persistence and receives remote commands.
By successfully brute-forcing SSH credentials across a list of captured IP addresses with open SSH ports, the botnet virus is intended to get first access. The external server ("ssh.ddos-cc[.]org"...

