New Linux Botnet Discovered
The SSHStalker botnet uses IRC C2 to control systems via legacy Linux kernel exploits.
There's a new bit of nastiness that's attacking Linux systems, by way of the Internet Relay Chat (IRC) communication protocol to execute command-and-control (C2) takeovers.
This new, old-school botnet, called SSHStalker, was discovered by the Flare research team using an SSH honeypot. During a two-month period, Flare detected several attempts revealing a fairly sophisticated operation that used old-school technology with modern automation.
According to the report, SSHStalker chains an SSH scanner with rapid staging to hand off enrollment into IRC channels, and it is optimized for scale.
The extensive report states, "We’ve designated this operation 'SSHStalker' due to its distinctive behavior: The botnet maintained persistent access without executing any observable impact operations, despite having in its arsenal capabilities to launch DDoS attacks and conduct cryptomining." The report continues, "This 'dormant persistence' pattern – infecting systems and establishing control without immediate monetization – differentiates it from typical opportunistic botnet operations and suggests either infrastructure staging, testing phases, or strategic access retention for future use."
Flare further states, “We found a file that indicates almost 7,000 fresh results from an ssh scanner. These results were from January 2026 in a very close proximity to the attack against our honeypot.”
Flare's scan results were dominated by cloud hosting providers, with IP addresses distributed throughout global regions (US, EU, APAC), a pattern that is consistent with "opportunistic automation or disposable attack infrastructure rather than dedicated nation-state or boutique hosting operations."
There are several mitigation suggestions in the report, including such things as monitoring for gcc, make, or build tool execution on production servers; using antivirus solutions to scan for malicious code; checking for cron jobs that execute every minute; and more.
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters
Support Our Work
Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.
News
-
Dutch Government Turns to Open Source for Digital Sovereignty
Following in the footsteps of European countries, the Netherlands is looking to increase its sovereign digital infrastructure with open source software.
-
Linux May Soon Work on Snapdragon X2-Based PCs
If you're thinking about buying a Snapdragon X2-based desktop or laptop, Linux may soon be an option.
-
KDE for People Initiative Calls for AI Ban in Plasma
A new community of KDE wants the project to adopt a strict no-AI policy for KDE Plasma.
-
KDE Sets Ambitious Goals for 2026 and Beyond
KDE Connect reveals the goals for the Linux desktop darling, with one of those goals long overdue.
-
It’s Time to Test Fedora 45 Beta
Fedora 45 beta has been released with updated Gnome, KDE Plasma, and kernel.
-
Ubuntu Stonking Stingray Gets Even Rustier
Ubuntu 26.10 has completed its migration to the Rust-based coreutils.
-
AI Fixes Linux Bottlenecks Using “Hideous” Code
A Linux developer used AI to fix bottlenecks that caused problems when building the kernel. The resulting AI-generated code needed a lot of work.
-
Advanced Video Coding Still Under Patent
Brazilian patent BRPI0109962B1 has expired, which means that DivX and Xvid are no longer problematic for Linux, but it doesn’t mean that video is all of a sudden fully unleashed.
-
2,000 Vulnerabilities per Linux Release
Thanks to AI bug hunters, the Linux kernel is seeing record numbers of vulnerabilities, and it's overwhelming developers.
-
Linux Exempt from California’s Age Verification Law
So long as Linux is distributed under the GPL, MIT, BSD, and Apache licenses, the OS is exempt from being required to verify the age of its users in California.
