A new SSH bot has been caught quietly logging into Linux systems, profiling their CPU, GPU, and memory, and then walking away without dropping any visible payload. The behavior looks harmless at first glance, yet everything about it points to carefully staged cryptomining activity waiting for the right hardware target. Instead of rushing to install malware, this bot takes time to weigh whether a compromised host is powerful enough to be worth mining on. The activity came to light when a DShield honeypot recorded an automated login that behaved very differently from the usual noisy password-guessing and one-line loader scripts. In a single session, the bot logged in as root, ran just two commands, profiled the host, tested...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!