216.73.217.22

Outlaw cybergang attacking targets worldwide

· Published 29/04/2025 16:27 · Modified 29/04/2025 21:52

Export JSON

Essential information

Published
29/04/2025 16:27
Modified
29/04/2025 21:52
Tags
2025-04-29 backdoor botnet crypto mining dota evasion irc linux outlaw persistence ssh xmrig
Related entities
1 intrusion sets (apt), 5 techniques (mitre), 3 malware, 8 others

Description

A recent incident response case in Brazil revealed a Perl-based called , also known as , targeting environments. The threat actor exploits weak credentials, downloads malicious scripts, and deploys an miner for Monero cryptocurrency. The includes an -based client that acts as a , allowing for various malicious activities. Victims have been identified mainly in the United States, with additional targets in Germany, Italy, Thailand, Singapore, Taiwan, Canada, and Brazil. The article provides detailed analysis of the malware's components, mechanisms, and techniques. Recommendations for system administrators include hardening configurations and implementing additional security measures to mitigate the risk of compromise.

External references