Threat reportMalwareTL-2026-1156
Multi-Malware Campaign Targeting Poorly Secured Linux SSH Servers — XMRig, ShellBot, MIG LogCleaner, XHide, and Go-based Propagation Tool
Multi-Malware Campaign Targeting Poorly Secured Linux SSH (TL-2026-1156), also tracked as Linux SSH Server Attack Distributing XMRig, ShellBot, and Other Malware, is a medium-severity malware campaign, first published 2026-07-03. It has no confirmed attribution, affects Generic Linux servers running OpenSSH with weak/default/reused, maps to 20 MITRE ATT&CK techniques (T1018, T1021.004, T1027.004), and is covered by 9 detection rules and 34 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 20MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 34Indicators of compromise
Key facts for TL-2026-1156
- Threat ID
- TL-2026-1156
- Also known as
- Linux SSH Server Attack Distributing XMRig, ShellBot, and Other Malware
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- any internet-facing linux server population no sector-specific targeting reported
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 34
Malware and tooling in Multi-Malware Campaign Targeting Poorly Secured Linux SSH
Malware and tooling: MIG LogCleaner, PerlBot, xmrig, XHide
How Multi-Malware Campaign Targeting Poorly Secured Linux SSH works
ASEC's Q2 2026 statistical report documents an ongoing campaign of brute-force/dictionary attacks against poorly managed Linux SSH servers. Following successful authentication, operators deploy XMRig (disguised as `mysql`), the Perl-based ShellBot IRC DDoS bot, MIG LogCleaner, the XHide process-name obfuscator, and a Go-based propagation tool (`meta`) that rescans SSH ports and reuses harvested credentials to self-propagate.
AhnLab Security Emergency response Center (ASEC) reports continued exploitation of Linux servers running poorly secured SSH services, consistent with campaigns it has tracked since at least 2018 (ShellBot/PerlBot lineage). Threat actors scan the internet for hosts with SSH (TCP/22) exposed, then run dictionary/brute-force attacks against weak or default credentials. Upon successful login, the attacker downloads a first-stage component named `run` from attacker infrastructure at download.xrpl.city, which in turn retrieves compressed archives (`auto.Jpg`, `pack.Jpg`) containing Shc-compiled shell scripts and ELF payloads. The payload set installs: (1) XMRig, a legitimate open-source Monero miner renamed/disguised as `mysql` to blend in with normal server processes and hijack CPU resources for cryptojacking; (2) ShellBot, distributed here under the `.b0t` alias, a Perl-based IRC bot capable of DDoS (HTTP/TCP/UDP flood commands) and remote command execution via IRC channel messages; (3) a Go-based propagation utility named `meta` that reads `ranges` (target IP/subnet lists) and `pass` (harvested/dictionary credential lists) configuration files to conduct further SSH port scanning and credential-stuffing against new targets, extending the botnet automatically; (4) MIG LogCleaner, a log-wiping utility used to erase authentication and shell history evidence of the intrusion; and (5) XHide, a process-name spoofing tool used to rename malicious processes to innocuous-looking names to evade casual `ps`/`top` inspection by administrators. No CVE or software vulnerability is involved — compromise is entirely credential-based (weak/default/reused SSH passwords), consistent with long-running Linux SSH cryptojacking/botnet campaigns such as Outlaw, Kinsing, and TeamTNT, which similarly combine SSH brute-forcing, XMRig deployment, and worm-like lateral propagation. ASEC recommends enforcing strong, periodically rotated SSH passwords, applying the latest OS/service patches, and restricting SSH exposure via firewalls and access-control products.
MITRE ATT&CK techniques used in TL-2026-1156
Discovery
T1018 Remote System Discovery; T1046 Network Service Discovery
Lateral Movement
Defense Evasion
T1027.004 Compile After Delivery; T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion
Persistence
T1053.003 Cron; T1098.004 SSH Authorized Keys
Execution
Command and Control
T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1571 Non-Standard Port
Initial Access
Credential Access
T1110.001 Password Guessing; T1110.002 Password Cracking
Impact
T1496.001 Compute Hijacking; T1498 Network Denial of Service
Resource Development
Reconnaissance
defense-impairment
Affected products and versions in Multi-Malware Campaign Targeting Poorly Secured Linux SSH
- Generic — Linux servers running OpenSSH with weak/default/reused credentials
Vulnerable versions: Any Linux distribution with internet-exposed SSH (TCP/22) using weak, default, or reused account passwords
Fixed in: Not applicable — credential-hygiene issue, not a software vulnerability
Remediation for Multi-Malware Campaign Targeting Poorly Secured Linux SSH
Immediate actions
- Rotate all SSH account passwords to strong, unique, non-dictionary values immediately on any internet-facing Linux host
- Audit SSH authorized_keys files and crontab entries on exposed hosts for unauthorized additions
- Block outbound/inbound traffic to download.xrpl.city and the listed C2 domains/IPs at the perimeter firewall
- Hunt for processes named mysql, meta, or unusual Shc-compiled binaries under /tmp, /var/tmp, and user home directories
- Search for and remove artifacts named run, auto.Jpg, pack.Jpg, ranges, pass, mig, .b0t
Workarounds
- Rate-limit or geofence SSH access where business requirements allow
- Change default SSH listening port as a low-value speed bump against mass scanners (not a substitute for credential hygiene)
Longer-term hardening
- Disable SSH password authentication in favor of key-based authentication with passphrase-protected keys
- Deploy fail2ban or equivalent brute-force lockout tooling on all SSH-exposed hosts
- Restrict SSH exposure to VPN/bastion access only; remove direct internet exposure of port 22 where possible
- Deploy EDR/behavioral monitoring on Linux fleets capable of detecting cryptomining process behavior and process-name spoofing
- Implement centralized, tamper-evident (remote/immutable) logging to defeat log-cleaner tools
Weaknesses (CWE) in Multi-Malware Campaign Targeting Poorly Secured Linux SSH
Timeline of Multi-Malware Campaign Targeting Poorly Secured Linux SSH
- ASEC's Q2 2026 observation window begins; campaign activity against poorly secured Linux SSH servers is ongoing/ambient during this period.
- Following authentication, the attacker downloads the first-stage `run` component from download.xrpl.city.
- Threat actors conduct brute-force/dictionary attacks against internet-exposed Linux SSH services with weak account credentials, gaining initial access upon success.
- ShellBot (distributed as `.b0t`) is installed and establishes an IRC-based command-and-control channel supporting DDoS and remote-command functionality.
- XMRig is deployed disguised as a `mysql` binary and begins Monero mining, consuming host CPU resources.
- Compressed Shc-compiled archives `auto.Jpg` and `pack.Jpg` are retrieved from attacker infrastructure and unpacked on the compromised host.
- XHide is used to rename malicious process names to evade casual administrator inspection via `ps`/`top`.
- MIG LogCleaner is run to erase authentication and shell-history log evidence of the intrusion.
- The Go-based propagation tool `meta` executes, reading `ranges` and `pass` configuration files to scan additional SSH targets and reuse harvested credentials for further spread.
- Close of ASEC's Q2 2026 statistical observation period covering this SSH malware campaign.
- ASEC publishes its Q2 2026 statistical report documenting this campaign, including malware samples, IOCs, and recommended mitigations.
Sources cited for Multi-Malware Campaign Targeting Poorly Secured Linux SSH
- ASEC: Linux SSH Server Attack Distributing XMRig, ShellBot, and Other Malware
- ASEC: ShellBot Malware Being Distributed to Linux SSH Servers
- SISA Threat-a-licious: ShellBot: A DDoS Bot targeting poorly managed Linux servers
- KPMG: Unique ShellBot DDoS Malware Targeting Linux Servers
- gbhackers: Legacy IRC Botnet Leverages Automated SSH Exploit Pipeline to Mass-Enroll Linux Hosts
- MITRE ATT&CK: Remote Services: SSH (T1021.004)
- MITRE ATT&CK: Resource Hijacking: Compute Hijacking (T1496.001)
- Red Canary Threat Detection Report: Linux Coinminers
- MITRE ATT&CK: Matrix - Enterprise - Linux
Detection coverage for TL-2026-1156
As of 2026-07-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1156 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.