216.73.216.6

Supershell Malware Being Distributed to Linux SSH Servers

· Published 20/09/2024 11:22 · Modified 20/09/2024 11:41

Export JSON

Essential information

Published
20/09/2024 11:22
Modified
20/09/2024 11:41
Tags
2024-09-20 cryptocurrency mining ssh supershell xmrig
Related entities
5 observables, 10 techniques (mitre), 2 malware

Description

A Chinese-developed Go-based backdoor called is targeting poorly managed Linux servers. The malware, which supports multiple platforms, primarily functions as a reverse shell for remote system control. Attackers use dictionary attacks from various IP addresses to gain access, then install directly or via a downloader script. The malware is downloaded from web and FTP servers. While is the initial payload for control hijacking, Monero CoinMiners are often installed alongside it, suggesting as the ultimate goal. To protect against such attacks, administrators should use strong passwords, update systems regularly, and implement security measures like firewalls.

External references