BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

New SSHStalker Linux Botnet Uses Old Exploits

SSHStalker botnet uses IRC, targets old Linux, stays persistent without activity, linked to Outlaw group.

  • A new botnet, SSHStalker, uses legacy IRC protocol for command-and-control and targets old Linux systems.
  • The operation is distinct for maintaining persistent access without immediate post-exploitation activity like crypto mining.
  • The threat toolset includes log cleaners, rootkits, and exploits for 16 vulnerabilities, some dating to 2009.
  • Researchers suspect a possible Romanian origin and connection to the known hacking group Outlaw (aka Dota).

Cybersecurity researchers from Flare have exposed a novel botnet operation, dubbed SSHStalker, which leverages the archaic Internet Relay Chat (IRC) protocol for command-and-control. This campaign uniquely scans for and compromises Linux systems with open SSH ports, then enlists them into IRC channels. However, unlike typical botnets that launch cryptocurrency mining or DDoS attacks, SSHStalker remains dormant post-infiltration.

- Advertisement -

Consequently, this persistent, low-profile access suggests the compromised infrastructure is being reserved for future strategic use. The malware employs a Golang scanner to propagate and deploys payloads, including an IRC bot, to await commands. Flare’s analysis reveals its toolkit blends stealth with legacy-era Linux exploitation, using a catalog of 16 distinct vulnerabilities impacting older kernels.

Furthermore, the attackers execute specialized programs to clean SSH connection logs from system files like utmp, wtmp, and lastlog, severely hampering forensic visibility. A “keep-alive” component ensures the malware process automatically restarts if terminated. The staging infrastructure also housed a repository of open-source tooling, including rootkits, crypto miners, and a script to steal exposed AWS secrets.

Researchers noted “Romanian-style nicknames, slang patterns, and naming conventions” within the operation’s IRC channels. Its operational fingerprint shows strong overlaps with the known hacking group Outlaw. Flare concluded the actor demonstrates “strong operational discipline in mass compromise workflows, infrastructure recycling, and long-tail persistence.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Coldcard adds user entropy to seed generation after $112M exploit

Coinkite released firmware 5.6.1 for Coldcard Mk4/Mk5 and 1.5.1Q for Coldcard Q, requiring user-supplied...

GitLab Flaw Actively Exploited After Disclosure

A critical GitLab vulnerability (CVE-2026-19478, CVSS 9.4) enables unauthenticated attackers to modify or delete...

PEPE Surges 25% Weekly, Outperforms Bitcoin and Ethereum

PEPE surged 14.2% in 24 hours and over 25% in the past week, outperforming...

Tom Lee: Avoid Robinhood Stock in 2026

Tom Lee of Fundstrat named Robinhood Markets Inc stock as one to avoid in...

MANTRA Token Plunges 18.5% as Chain Halts After Incident

MANTRA's native token plunged 18.5% to an all-time low of $0.004126 before the chain...

Must Read

9 DePIN Programs For Passive Income

Here’s something most people don’t realize: your smartphone and PC can generate passive income with almost no effort.I’m not talking about clicking ads for...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading