216.73.217.22

Q1 2026 Malware Statistics Report for Linux SSH Servers

· Published 14/04/2026 08:54 · Modified 14/04/2026 09:52

Export JSON

Essential information

Published
14/04/2026 08:54
Modified
14/04/2026 09:52
Tags
2026-04-14 chinese attribution coinminer credential attacks ddos botnet gafgyt honeypot analysis linux servers mirai p2pinfect prometei shellbot ssh brute-force tsunami v2ray v2ray proxy xmrig xorddos
Related entities
1 observables, 16 techniques (mitre), 10 malware

Description

Analysis of attacks against Linux SSH servers during Q1 2026 reveals worm as the dominant threat, representing 70.3% of all attack sources. DDoS botnets including , , , and were identified as primary threats. A notable campaign involved installing tools on compromised systems, attributed to a suspected Chinese threat actor. Attackers employed techniques to gain access, executed reconnaissance commands to assess system information, and deployed for proxy node operations. The campaign targeted poorly secured SSH servers with weak credentials, emphasizing the need for strong password policies, access controls, and network monitoring to detect unusual outbound connections and proxy-related activities.

External references