EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

IoT devices and Linux-based systems targeted by OpenSSH trojan campaign

Verified open source
Intelligence with traceable provenance. EudorIA retains technical indicators acquired from supported feeds, with source, date and context. Shareable IOCs are available in the STIX feeds; detection and blocking actions require an assessment of validity, confidence and applicability to the customer's environment. Browse STIX feeds
EudorIA operational summary

What it means

Priority 85/100

Un'attività di attacco mira a dispositivi IoT e sistemi Linux tramite un trojan OpenSSH. Gli attaccanti sfruttano credenziali vulnerabili, installano malware per minare criptovalute e utilizzano rootkit per evadere la rilevazione. La patch di OpenSSH permette accesso persistente e occultazione delle attività. La soluzione richiede patching, monitoraggio e mitigazione delle vulnerabilità.

Why it matters

Per le PMI italiane, il rischio è elevato poiché dispositivi IoT e sistemi Linux sono spesso esposti a Internet. L'attacco può compromettere la disponibilità e la sicurezza dei dati, con costi elevati per la gestione del rischio e la riparazione.

MITRE ATT&CKT1190 · Exploit Public-Facing Application *T1078 · Valid Accounts *T1486 · Data Encrypted for Impact *T1059 · Command and Scripting Interpreter *
Brief generato da un modello locale EudorIA (qwen3:8b@workstation-gpu) a partire dal testo della fonte. Verificare sulla fonte prima di decisioni operative; le tecniche con * sono inferite dal modello. Analisi basata su fonte editoriale e dettagli parziali non pubblicati in modo completo. Alcuni dettagli tecnici non sono verificabili in modo totale senza accesso al sistema interessato.

Estratto della fonte usato dal modello

Cyberattacker techniques, tools, and infrastructure Microsoft Defender for Endpoint Microsoft Defender for IoT Cryptojacking, the illicit use of computing resources to mine cryptocurrency, has become increasingly prevalent in recent years, with attackers building a cybercriminal economy around attack tools, infrastructure, and services to generate revenue from targeting a wide range of vulnerable systems, including Internet of Things (IoT) devices. Microsoft researchers have recently discovered an attack leveraging custom and open-source tools to target internet-facing Linux-based systems and IoT devices. The attack uses a patched version of OpenSSH to take control of impacted devices and install cryptomining malware. Utilizing an established criminal infrastructure that has incorporated the use of a Southeast Asian financial institution’s subdomain as a command and control (C2) server, the threat actors behind the attack use a backdoor that deploys a wide array of tools and components such as rootkits and an IRC bot to steal device resources for mining operations. The backdoor also installs a patched version of OpenSSH on affected devices, allowing threat actors to hijack SSH credentials, move laterally within the network, and conceal malicious SSH connections. The complexity and scope of this attack are indicative of the efforts attackers make to evade detection. In this blog post, we present our analysis of the tools and techniques used in this attack and the efforts made

Potential operational benefits

  • Riduzione della superficie esposta a attacchi
  • Miglioramento della rilevazione e risposta agli incidenti
  • Minimizzazione del rischio di minacce persistenti
  • Aumento della conformità alle normative di sicurezza
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsFirewall NGFW / IPSEDR / XDRPatch managementMonitoraggio / SIEMSegmentazione di rete
AudienceITSOCCISO

Text acquired from the source

Evento MISP pubblicato con TLP:CLEAR: IoT devices and Linux-based systems targeted by OpenSSH trojan campaign.

Source
MISP EudorIA
Publishing entity
MISP EudorIA
Entity type
Intelligence community
Area
Global
Original language
it · translation not needed
Publication
30/07/2026 02:49
Sharing
TLP:CLEAR
Indicators reported by the source
95
IOCs indexed for lookup
0 values within the retention period
IOCs available in the STIX feed
93Last sharing verification: 2026-09-26T05:00:59.865593+00:00
MISP event
0ee609d4-c99f-428c-a7f3-0afa7efe01b6
MITRE ATT&CK
T1190, T1077, T1078, T1079, T1080, T1081, T1486, T1059
Classification
High
Open the original source