This new Linux malware floods machines with cryptominers and DDoS bots

Linux machines are being targeted with XMRig malware

When you purchase through links on our site, we may earn an affiliate commission.Here’s how it works.

Cybersecurity researchers have spotted a new Linuxmalwaredownloader that targets poorly defended Linux servers with cryptocurrency miners and DDoS IRC bots.

Researchers from ASEC discovered the attack after the Shell Script Compiler (SHC) used to create the downloader was uploaded to VirusTotal. Apparently, Korean users were the ones uploading the SHC, and it’s Korean users who are targets, as well.

Further analysis has shown that the threat actors are going after poorly defendedLinuxservers, brute-forcing their way into administrator accounts over SSH.

Mining Monero

Mining Monero

Once they make their way in, they’ll either install a cryptocurrency miner, or a DDoS IRC bot. The miner being deployed is XMRig, arguably the most popular cryptocurrency miner among hackers. It uses the computing power of a victim’sendpointsto generate Monero, a privacy-oriented cryptocurrency whose transactions are seemingly impossible to track, and whose users are allegedly impossible to identify.

For the DDoS IRC bot, the threat actors can use it to run commands such as TCP Flood, UDP Flood, or HTTP Flood. They can run port scanning, Nmap scanning, kill various processes, clean up the logs, and more.

Linux systems are being bombarded with ransomware and cryptojacking attacks>Windows and Linux servers turned into crypto miners>These are the best firewalls right now

“Because of this, administrators should use passwords that are difficult to guess for their accounts and change them periodically to protect the Linux server from brute force attacks and dictionary attacks, and update to the latest patch to prevent vulnerability attacks,” ASEC said in its report.

“Administrators should also use security programs such as firewalls for servers accessible from outside to restrict access by attackers.”

Are you a pro? Subscribe to our newsletter

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Linux systems are being constantly bombarded with malicious deployments, most oftenransomwareand cryptojacking.

A VMware report from February 2022 said the continued success of Linux services in the digital infrastructure and cloud industries, as well as the fact that most anti-malware and cybersecurity solutions are focused on protecting Windows-based devices, put Linux on thin ice.

Via:BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

This new phishing strategy utilizes GitHub comments to distribute malware

Should your VPN always be on?

VIPRE Security Group says its new endpoint protection tools can stamp out even the latest cybersecurity threats