Threat reportMalwareTL-2026-1156

Multi-Malware Campaign Targeting Poorly Secured Linux SSH Servers — XMRig, ShellBot, MIG LogCleaner, XHide, and Go-based Propagation Tool

mediumACTIVE

Multi-Malware Campaign Targeting Poorly Secured Linux SSH (TL-2026-1156), also tracked as Linux SSH Server Attack Distributing XMRig, ShellBot, and Other Malware, is a medium-severity malware campaign, first published 2026-07-03. It has no confirmed attribution, affects Generic Linux servers running OpenSSH with weak/default/reused, maps to 20 MITRE ATT&CK techniques (T1018, T1021.004, T1027.004), and is covered by 9 detection rules and 34 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
20MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
34Indicators of compromise

Key facts for TL-2026-1156

Threat ID
TL-2026-1156
Also known as
Linux SSH Server Attack Distributing XMRig, ShellBot, and Other Malware
Severity
MEDIUM
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
any internet-facing linux server population no sector-specific targeting reported
Target regions
Global
Detection rules
9
Indicators of compromise
34

Malware and tooling in Multi-Malware Campaign Targeting Poorly Secured Linux SSH

Malware and tooling: MIG LogCleaner, PerlBot, xmrig, XHide

How Multi-Malware Campaign Targeting Poorly Secured Linux SSH works

ASEC's Q2 2026 statistical report documents an ongoing campaign of brute-force/dictionary attacks against poorly managed Linux SSH servers. Following successful authentication, operators deploy XMRig (disguised as `mysql`), the Perl-based ShellBot IRC DDoS bot, MIG LogCleaner, the XHide process-name obfuscator, and a Go-based propagation tool (`meta`) that rescans SSH ports and reuses harvested credentials to self-propagate.

AhnLab Security Emergency response Center (ASEC) reports continued exploitation of Linux servers running poorly secured SSH services, consistent with campaigns it has tracked since at least 2018 (ShellBot/PerlBot lineage). Threat actors scan the internet for hosts with SSH (TCP/22) exposed, then run dictionary/brute-force attacks against weak or default credentials. Upon successful login, the attacker downloads a first-stage component named `run` from attacker infrastructure at download.xrpl.city, which in turn retrieves compressed archives (`auto.Jpg`, `pack.Jpg`) containing Shc-compiled shell scripts and ELF payloads. The payload set installs: (1) XMRig, a legitimate open-source Monero miner renamed/disguised as `mysql` to blend in with normal server processes and hijack CPU resources for cryptojacking; (2) ShellBot, distributed here under the `.b0t` alias, a Perl-based IRC bot capable of DDoS (HTTP/TCP/UDP flood commands) and remote command execution via IRC channel messages; (3) a Go-based propagation utility named `meta` that reads `ranges` (target IP/subnet lists) and `pass` (harvested/dictionary credential lists) configuration files to conduct further SSH port scanning and credential-stuffing against new targets, extending the botnet automatically; (4) MIG LogCleaner, a log-wiping utility used to erase authentication and shell history evidence of the intrusion; and (5) XHide, a process-name spoofing tool used to rename malicious processes to innocuous-looking names to evade casual `ps`/`top` inspection by administrators. No CVE or software vulnerability is involved — compromise is entirely credential-based (weak/default/reused SSH passwords), consistent with long-running Linux SSH cryptojacking/botnet campaigns such as Outlaw, Kinsing, and TeamTNT, which similarly combine SSH brute-forcing, XMRig deployment, and worm-like lateral propagation. ASEC recommends enforcing strong, periodically rotated SSH passwords, applying the latest OS/service patches, and restricting SSH exposure via firewalls and access-control products.

MITRE ATT&CK techniques used in TL-2026-1156

Discovery

T1018 Remote System Discovery; T1046 Network Service Discovery

Lateral Movement

T1021.004 SSH

Defense Evasion

T1027.004 Compile After Delivery; T1036.005 Match Legitimate Resource Name or Location; T1070.004 File Deletion

Persistence

T1053.003 Cron; T1098.004 SSH Authorized Keys

Execution

T1059.004 Unix Shell

Command and Control

T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1571 Non-Standard Port

Initial Access

T1078 Valid Accounts

Credential Access

T1110.001 Password Guessing; T1110.002 Password Cracking

Impact

T1496.001 Compute Hijacking; T1498 Network Denial of Service

Resource Development

T1583.001 Domains

Reconnaissance

T1595.001 Scanning IP Blocks

defense-impairment

T1685.006 Clear Linux or Mac System Logs

Affected products and versions in Multi-Malware Campaign Targeting Poorly Secured Linux SSH

  • Generic — Linux servers running OpenSSH with weak/default/reused credentials
    Vulnerable versions: Any Linux distribution with internet-exposed SSH (TCP/22) using weak, default, or reused account passwords
    Fixed in: Not applicable — credential-hygiene issue, not a software vulnerability

Remediation for Multi-Malware Campaign Targeting Poorly Secured Linux SSH

Immediate actions

  • Rotate all SSH account passwords to strong, unique, non-dictionary values immediately on any internet-facing Linux host
  • Audit SSH authorized_keys files and crontab entries on exposed hosts for unauthorized additions
  • Block outbound/inbound traffic to download.xrpl.city and the listed C2 domains/IPs at the perimeter firewall
  • Hunt for processes named mysql, meta, or unusual Shc-compiled binaries under /tmp, /var/tmp, and user home directories
  • Search for and remove artifacts named run, auto.Jpg, pack.Jpg, ranges, pass, mig, .b0t

Workarounds

  • Rate-limit or geofence SSH access where business requirements allow
  • Change default SSH listening port as a low-value speed bump against mass scanners (not a substitute for credential hygiene)

Longer-term hardening

  • Disable SSH password authentication in favor of key-based authentication with passphrase-protected keys
  • Deploy fail2ban or equivalent brute-force lockout tooling on all SSH-exposed hosts
  • Restrict SSH exposure to VPN/bastion access only; remove direct internet exposure of port 22 where possible
  • Deploy EDR/behavioral monitoring on Linux fleets capable of detecting cryptomining process behavior and process-name spoofing
  • Implement centralized, tamper-evident (remote/immutable) logging to defeat log-cleaner tools

Weaknesses (CWE) in Multi-Malware Campaign Targeting Poorly Secured Linux SSH

CWE-521, CWE-1188

Timeline of Multi-Malware Campaign Targeting Poorly Secured Linux SSH

  • ASEC's Q2 2026 observation window begins; campaign activity against poorly secured Linux SSH servers is ongoing/ambient during this period.
  • Following authentication, the attacker downloads the first-stage `run` component from download.xrpl.city.
  • Threat actors conduct brute-force/dictionary attacks against internet-exposed Linux SSH services with weak account credentials, gaining initial access upon success.
  • ShellBot (distributed as `.b0t`) is installed and establishes an IRC-based command-and-control channel supporting DDoS and remote-command functionality.
  • XMRig is deployed disguised as a `mysql` binary and begins Monero mining, consuming host CPU resources.
  • Compressed Shc-compiled archives `auto.Jpg` and `pack.Jpg` are retrieved from attacker infrastructure and unpacked on the compromised host.
  • XHide is used to rename malicious process names to evade casual administrator inspection via `ps`/`top`.
  • MIG LogCleaner is run to erase authentication and shell-history log evidence of the intrusion.
  • The Go-based propagation tool `meta` executes, reading `ranges` and `pass` configuration files to scan additional SSH targets and reuse harvested credentials for further spread.
  • Close of ASEC's Q2 2026 statistical observation period covering this SSH malware campaign.
  • ASEC publishes its Q2 2026 statistical report documenting this campaign, including malware samples, IOCs, and recommended mitigations.

Sources cited for Multi-Malware Campaign Targeting Poorly Secured Linux SSH

Detection coverage for TL-2026-1156

As of 2026-07-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1156 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
34 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats