• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Friday, September 12, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

Compromised Linux SSH servers engage in DDoS attacks, cryptomining

20 June 2023
in Mining
Reading Time: 2 mins read
A A
0
Compromised Linux SSH servers engage in DDoS attacks, cryptomining
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

Related articles

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024

Poorly managed Linux SSH servers are getting compromised by unknown attackers and instructed to engage in DDoS attacks while simultaneously mining cryptocurrency in the background.

The Tsunami DDoS bot

Tsunami, also known as Kaiten, is a type of DDoS bot that is frequently distributed alongside malware strains like Mirai and Gafgyt.

What sets Tsunami apart from other DDoS bots is the fact that it functions as an internet relay chat (IRC) bot, meaning it uses IRC to communicate with the threat actor.

“The source code of Tsunami is publicly available so it is used by a multitude of threat actors. Among its various uses, it is mostly used in attacks against IoT devices. Of course, it is also consistently used to target Linux servers,” researchers with AhnLab’s Security Emergency response Center (ASEC) explained.

Attack on Linux SSH servers

A threat actor is mounting dictionary attacks to log into Linux servers with SSH installed and saddle the server with the Tsunami and ShellBot DDoS bots, the XMRig CoinMiner program, and Log Cleaner – a tool for deleting and modifying logs.

“Among the malware that are installed, the ‘key’ file is a downloader-type Bash script that installs additional malware. In addition to being a downloader, it also performs various preliminary tasks to take control of infected systems, which includes installing a backdoor SSH account,” ASEC researchers noted.

Both Tsunami and ShellBot use the IRC protocol to transmit stolen information to the C2 server and receive instructions from it.

Log Cleaner is likely installed to hide malicious activity and hinder future attempts to investigate the breach. XMRig is installed to mine cryptocurrency.

Attack prevention and clean-up

Preventing this type of attack is not difficult: admins should choose strong, unique passwords; enable multi-factor authentication on their SSH account; and set up firewalls to block malicious access attempts and prevent unauthorized entry into the system.

In the event that a Linux system has been compromised, administrators should leverage the IoCs shared by security researchers to eliminate malware and malicious scripts from the system.

In these specific attacks, the threat actors also create an SSH backdoor account, which serves as a fail-safe measure to retain access to the system in case administrators change the password of the primary admin account. That account should also be removed.

Finally, blocking the malware’s communication traffic to C2 servers is vital, to prevent data exfiltration and delivery of instructions.

Source link

Cryptohopper
ADVERTISEMENT
[crypto-donation-box]
Tags: AttacksCompromisedCryptoMiningDDoSengageLinuxServersSSH
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Here’s what happened in crypto today? DOGE, ETH, BTC, XRP, SHIB, ApeMax, Tether

Next Post

How to Earn Passive Income From NFTs

Related Posts

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
0

A fake news story circulated today about Russia’s supposed embrace of bitcoin mining and crypto payments. According to excited social...

New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
0

A new report estimates a $20 billion revenue opportunity in Bitcoin BTC/USD mining chips and hardware over the next five...

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

30 July 2024
0

(Bloomberg) -- Russia is moving to regulate the use of cryptocurrencies, as companies wrestle with increasing difficulties in foreign payments...

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

30 July 2024
0

The Russian central bank plans to initiate international payments in cryptocurrencies by the end of the year to overcome delays...

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

30 July 2024
0

Listed both on Wall Street and the London Stock Exchange (LSE) Bitcoin miner Argo Blockchain, has announced a £6.5 million...

Load More
Next Post
How to Earn Passive Income From NFTs

How to Earn Passive Income From NFTs

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
Solana News: Galaxy Digital CEO Explains Why This Is the 'Season of SOL' – CoinDesk

Solana News: Galaxy Digital CEO Explains Why This Is the 'Season of SOL' – CoinDesk

12 September 2025
Solana (SOL) Price Prediction 2025 – Can the Bull Run Push It to ,000?

Solana (SOL) Price Prediction 2025 – Can the Bull Run Push It to $1,000?

12 September 2025
Solana Surges as TVL Hits B and Market Cap Overtakes BNB – CoinCentral

Solana Surges as TVL Hits $13B and Market Cap Overtakes BNB – CoinCentral

12 September 2025
Most big cryptocurrencies rise as Solana rallies – MarketWatch

Most big cryptocurrencies rise as Solana rallies – MarketWatch

12 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • Solana News: Galaxy Digital CEO Explains Why This Is the 'Season of SOL' – CoinDesk
  • Solana (SOL) Price Prediction 2025 – Can the Bull Run Push It to $1,000?
  • Solana Surges as TVL Hits $13B and Market Cap Overtakes BNB – CoinCentral
  • Most big cryptocurrencies rise as Solana rallies – MarketWatch
  • WLFI Burn Proposal Targets 50% Price Surge With Buybacks

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 115,842.00
  • ethereumEthereum (ETH) $ 4,608.01
  • xrpXRP (XRP) $ 3.07
  • tetherTether (USDT) $ 1.00
  • solanaSolana (SOL) $ 240.56
  • bnbBNB (BNB) $ 917.57
  • usd-coinUSDC (USDC) $ 0.999805
  • dogecoinDogecoin (DOGE) $ 0.269993
  • staked-etherLido Staked Ether (STETH) $ 4,601.89
  • tronTRON (TRX) $ 0.350192
  • cardanoCardano (ADA) $ 0.903161
  • wrapped-stethWrapped stETH (WSTETH) $ 5,595.55
  • chainlinkChainlink (LINK) $ 24.79
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,972.43
  • hyperliquidHyperliquid (HYPE) $ 55.94
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 115,863.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.67
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • stellarStellar (XLM) $ 0.396163
  • wrapped-eethWrapped eETH (WEETH) $ 4,959.29
  • avalanche-2Avalanche (AVAX) $ 28.60
  • bitcoin-cashBitcoin Cash (BCH) $ 595.76
  • wethWETH (WETH) $ 4,615.03
  • hedera-hashgraphHedera (HBAR) $ 0.243150
  • litecoinLitecoin (LTC) $ 117.49
  • leo-tokenLEO Token (LEO) $ 9.59
  • crypto-com-chainCronos (CRO) $ 0.255313
  • the-open-networkToncoin (TON) $ 3.20
  • shiba-inuShiba Inu (SHIB) $ 0.000014
  • usdsUSDS (USDS) $ 0.999565
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 115,922.00
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • polkadotPolkadot (DOT) $ 4.25
  • whitebitWhiteBIT Coin (WBT) $ 44.15
  • uniswapUniswap (UNI) $ 10.10
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.209276
  • ethenaEthena (ENA) $ 0.766403
  • mantleMantle (MNT) $ 1.61
  • moneroMonero (XMR) $ 277.46
  • aaveAave (AAVE) $ 317.02
  • pepePepe (PEPE) $ 0.000011
  • bitget-tokenBitget Token (BGB) $ 4.93
  • daiDai (DAI) $ 0.999952
  • okbOKB (OKB) $ 196.47
  • memecoreMemeCore (M) $ 2.38
  • jito-staked-solJito Staked SOL (JITOSOL) $ 295.95
  • myx-financeMYX Finance (MYX) $ 18.45
  • ondo-financeOndo (ONDO) $ 1.10