Tag: SSHStalker Botnet

SSHStalker Botnet Uses IRC C2 to Control Linux Systems via Legacy Kernel Exploits
News

SSHStalker Botnet Uses IRC C2 to Control Linux Systems via Legacy Kernel Exploits

Details of a new botnet operation known as SSHStalker, which uses the Internet Relay Chat (IRC) communication protocol for command-and-control (C2) purposes, have been made public by cybersecurity researchers. The arsenal combines legacy-era Linux exploitation with stealth helpers: "The actor maintains a sizable back-catalog of Linux 2.6.x-era exploits (2009–2010 CVEs) in addition to log cleaners (utmp/wtmp/lastlog tampering) and rootkit-class artifacts," cybersecurity firm Flare stated. "Remaining effective against long-tail legacy environments and 'forgotten' infrastructure, these are low value against newer stacks. An SSH scanner and other easily accessible scanners are used by SSHStalker, an automated mass-compromise operation that combines IRC botnet mechanics with the ability ...