Linux servers are being infected with a dangerous new malware


Cybersecurity firm AhnLab’s Security Emergency response Center (ASEC) has uncovered an attack against, “inadequately managed” Linux SSH servers whereby malware is being installed and spread.
Most notable has been the installation of a Tsunami DDoS Bot, but ShellBot, XMRig CoinMiner, and Log Cleaner malware have also all been spotted.
Because Tsunami’s source code is publicly available, it has been used in numerous attacks against IoT devices and is often seen deployed alongside Mirai and Gafgyt, though Tsunami attacks on Linux servers are just as common.
Linux servers are being attacked by multiple malware
AhnLab says that the Secure Shell (SSH) service is prone to poor management, thus is a perfect opportunity for threat actors to exploit for attacks. SSH enables admins to log in remotely and control the system, but cyberattackers can also gain unauthorized access through brute force or a dictionary attack.
Alongside the DDoS bot that allows the execution of additional malicious commands, the CoinMiner can be especially detrimental to the performance of a machine as it gets to work mining for Monero.
The Log Cleaner also serves an important purpose in the attack as it assists in wiping away evidence of the attack, thus making it harder for victims to identify that their machine has become the subject.
While the consequences can be painful for IT admins, there are a few really simple steps that AhnLab highlights which can be taken to protect Linux servers from such attacks.
Just like with any account, the cybersecurity firm recommends regularly changing the password which it says will help “protect the Linux server from brute force attacks and dictionary attacks.” Users should also frequently check for updates and patches, even with automatic updates enabled, to be able to iron out any bugs and vulnerabilities along the way.
Cybersecurity firm AhnLab’s Security Emergency response Center (ASEC) has uncovered an attack against, “inadequately managed” Linux SSH servers whereby malware is being installed and spread. Most notable has been the installation of a Tsunami DDoS Bot, but ShellBot, XMRig CoinMiner, and Log Cleaner malware have also all been spotted. Because Tsunami’s…
Recent Posts
- Your new favorite teacher might be this AI educator that never loses their patience
- Kia’s next EV is the affordable, long-range EV4 sedan
- Meta’s AI chatbot will soon have a standalone app
- Framework’s Laptop 12 Could Inject New Life Into Budget Portable PCs
- CRKD teamed up with Gibson to make new guitar controllers
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010