# Multi-Malware Campaign Targeting Poorly Secured Linux SSH Servers — XMRig, ShellBot, MIG LogCleaner, XHide, and Go-based Propagation Tool

> ASEC's Q2 2026 statistical report documents an ongoing campaign of brute-force/dictionary attacks against poorly managed Linux SSH servers. Following successful authentication, operators deploy XMRig (disguised as `mysql`), the Perl-based ShellBot IRC DDoS bot, MIG LogCleaner, the XHide process-name obfuscator, and a Go-based propagation tool (`meta`) that rescans SSH ports and reuses harvested credentials to self-propagate.

- **Published:** 2026-07-03T00:00:00Z
- **Last reviewed:** 2026-07-03T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1156
- **ID:** TL-2026-1156
- **Severity:** MEDIUM
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 34 (full data via the Threadlinqs MCP server — Purple tier)

## Description

AhnLab Security Emergency response Center (ASEC) reports continued exploitation of Linux servers running poorly secured SSH services, consistent with campaigns it has tracked since at least 2018 (ShellBot/PerlBot lineage). Threat actors scan the internet for hosts with SSH (TCP/22) exposed, then run dictionary/brute-force attacks against weak or default credentials. Upon successful login, the attacker downloads a first-stage component named `run` from attacker infrastructure at download.xrpl.city, which in turn retrieves compressed archives (`auto.Jpg`, `pack.Jpg`) containing Shc-compiled shell scripts and ELF payloads. The payload set installs: (1) XMRig, a legitimate open-source Monero miner renamed/disguised as `mysql` to blend in with normal server processes and hijack CPU resources for cryptojacking; (2) ShellBot, distributed here under the `.b0t` alias, a Perl-based IRC bot capable of DDoS (HTTP/TCP/UDP flood commands) and remote command execution via IRC channel messages; (3) a Go-based propagation utility named `meta` that reads `ranges` (target IP/subnet lists) and `pass` (harvested/dictionary credential lists) configuration files to conduct further SSH port scanning and credential-stuffing against new targets, extending the botnet automatically; (4) MIG LogCleaner, a log-wiping utility used to erase authentication and shell history evidence of the intrusion; and (5) XHide, a process-name spoofing tool used to rename malicious processes to innocuous-looking names to evade casual `ps`/`top` inspection by administrators. No CVE or software vulnerability is involved — compromise is entirely credential-based (weak/default/reused SSH passwords), consistent with long-running Linux SSH cryptojacking/botnet campaigns such as Outlaw, Kinsing, and TeamTNT, which similarly combine SSH brute-forcing, XMRig deployment, and worm-like lateral propagation. ASEC recommends enforcing strong, periodically rotated SSH passwords, applying the latest OS/service patches, and restricting SSH exposure via firewalls and access-control products.

## MITRE ATT&CK

- T1595.001 Scanning IP Blocks
- T1583.001 Domains
- T1078 Valid Accounts
- T1110.001 Password Guessing
- T1110.002 Password Cracking
- T1059.004 Unix Shell
- T1098.004 SSH Authorized Keys
- T1053.003 Cron
- T1036.005 Match Legitimate Resource Name or Location
- T1685.006 Clear Linux or Mac System Logs
- T1070.004 File Deletion
- T1027.004 Compile After Delivery
- T1046 Network Service Discovery
- T1018 Remote System Discovery
- T1021.004 SSH
- T1071.001 Web Protocols
- T1105 Ingress Tool Transfer
- T1571 Non-Standard Port
- T1496.001 Compute Hijacking
- T1498 Network Denial of Service

## Sources

- [ASEC: Linux SSH Server Attack Distributing XMRig, ShellBot, and Other Malware](https://asec.ahnlab.com/en/94396/)
- [ASEC: ShellBot Malware Being Distributed to Linux SSH Servers](https://asec.ahnlab.com/en/49769/)
- [SISA Threat-a-licious: ShellBot: A DDoS Bot targeting poorly managed Linux servers](https://www.sisainfosec.com/threat-a-licious/shellbot-a-ddos-bot-targeting-poorly-managed-linux-servers/)
- [KPMG: Unique ShellBot DDoS Malware Targeting Linux Servers](https://assets.kpmg.com/content/dam/kpmgsites/in/pdf/2023/03/24-march-2023-unique-shellbot-ddos-malware-targeting-linux-servers.pdf.coredownload.inline.pdf)
- [gbhackers: Legacy IRC Botnet Leverages Automated SSH Exploit Pipeline to Mass-Enroll Linux Hosts](https://gbhackers.com/legacy-irc-botnet/)
- [MITRE ATT&CK: Remote Services: SSH (T1021.004)](https://attack.mitre.org/techniques/T1021/004/)
- [MITRE ATT&CK: Resource Hijacking: Compute Hijacking (T1496.001)](https://attack.mitre.org/techniques/T1496/001/)
- [Red Canary Threat Detection Report: Linux Coinminers](https://redcanary.com/threat-detection-report/trends/linux-coinminers/)
- [MITRE ATT&CK: Matrix - Enterprise - Linux](https://attack.mitre.org/matrices/enterprise/linux/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1156
