Linux servers are being infected with a dangerous new malware

Magnifying glass enlarging the word 'malware' in computer machine code
(Image credit: Shutterstock)

Cybersecurity firm AhnLab’s Security Emergency response Center (ASEC) has uncovered an attack against, “inadequately managed” Linux SSH servers whereby malware is being installed and spread.

Most notable has been the installation of a Tsunami DDoS Bot, but ShellBot, XMRig CoinMiner, and Log Cleaner malware have also all been spotted.

Because Tsunami’s source code is publicly available, it has been used in numerous attacks against IoT devices and is often seen deployed alongside Mirai and Gafgyt, though Tsunami attacks on Linux servers are just as common.

Linux servers are being attacked by multiple malware

AhnLab says that the Secure Shell (SSH) service is prone to poor management, thus is a perfect opportunity for threat actors to exploit for attacks. SSH enables admins to log in remotely and control the system, but cyberattackers can also gain unauthorized access through brute force or a dictionary attack.

Alongside the DDoS bot that allows the execution of additional malicious commands, the CoinMiner can be especially detrimental to the performance of a machine as it gets to work mining for Monero.

The Log Cleaner also serves an important purpose in the attack as it assists in wiping away evidence of the attack, thus making it harder for victims to identify that their machine has become the subject.

While the consequences can be painful for IT admins, there are a few really simple steps that AhnLab highlights which can be taken to protect Linux servers from such attacks. 

Just like with any account, the cybersecurity firm recommends regularly changing the password which it says will help “protect the Linux server from brute force attacks and dictionary attacks.” Users should also frequently check for updates and patches, even with automatic updates enabled, to be able to iron out any bugs and vulnerabilities along the way.

TOPICS
Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
Close up of the Linux penguin.
A new Linux backdoor is hitting US universities and governments
China
Chinese hackers develop effective new hacking technique to go after business networks
A person holding out their hand with a digital AI symbol.
This ransomware gang is using SSH tunnels to target VMware appliances
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Huge cybercrime attack sees 390,000 WordPress websites hit, details stolen
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Industrial routers are being hit by zero-days from new Mirai botnets
Representational image depecting cybersecurity protection
OpenSSH vulnerabilities could pose huge threat to businesses everywhere
Latest in Pro
An abstract image of a lock against a digital background, denoting cybersecurity.
Cyber resilience under DORA – are you prepared for the challenge?
Sam Altman and OpenAI
UK regulator clears Microsoft’s $13bn deal with OpenAI after lengthy delay
A person holding out their hand with a digital AI symbol.
The decision-maker's playbook: integrating Generative AI for optimal results
AMD Ryzen 9950X
Ryzen CPUs are the cheapest Zen 5 cores you can buy, but I was surprised to see this AMD 192-core CPUs on the value leaderboard
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Latest in News
A screenshot showing Naoe looking at the hidden blade in Assassin's Creed Shadows
Prep 107GB of space as Assassin's Creed Shadows preload and expected global release times are shared by Ubisoft
Sam Altman and OpenAI
UK regulator clears Microsoft’s $13bn deal with OpenAI after lengthy delay
Google AI Mode
Google previews AI Mode for search, taking on the likes of ChatGPT search and Perplexity
AMD Ryzen 9950X
Ryzen CPUs are the cheapest Zen 5 cores you can buy, but I was surprised to see this AMD 192-core CPUs on the value leaderboard
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why