216.73.216.6

Outlaw Linux Malware: Persistent, Unsophisticated, and Surprisingly Effective

· Published 03/04/2025 22:07 · Modified 04/04/2025 07:26

Export JSON

Essential information

Published
03/04/2025 22:07
Modified
04/04/2025 07:26
Tags
2025-04-03 blitz botnet brute-force cryptocurrency mining irc linux outlaw persistence ssh stealth shellbot worm xmrig
Related entities
87 observables, 1 intrusion sets (apt), 11 techniques (mitre), 4 malware

Description

is a persistent malware that uses basic techniques like brute-forcing, key manipulation, and cron-based to maintain a long-lasting . Despite its lack of sophistication, it remains active by leveraging simple but impactful tactics. The malware deploys modified miners, uses for command and control, and includes publicly available scripts for and defense evasion. 's infection chain spans nearly the entire MITRE ATT&CK framework, offering many detection opportunities. It propagates in a -like manner, using compromised hosts to launch further attacks on local subnets, rapidly expanding the .

External references