IoT devices and Linux-based systems targeted by OpenSSH trojan campaign
What it means
Un'attività di attacco mira a dispositivi IoT e sistemi Linux tramite un trojan OpenSSH. Gli attaccanti sfruttano credenziali vulnerabili, installano malware per minare criptovalute e utilizzano rootkit per evadere la rilevazione. La patch di OpenSSH permette accesso persistente e occultazione delle attività. La soluzione richiede patching, monitoraggio e mitigazione delle vulnerabilità.
Why it matters
Per le PMI italiane, il rischio è elevato poiché dispositivi IoT e sistemi Linux sono spesso esposti a Internet. L'attacco può compromettere la disponibilità e la sicurezza dei dati, con costi elevati per la gestione del rischio e la riparazione.
Recommended actions
- Applica patch di sicurezza per OpenSSH
- Disabilita accesso SSH non necessario e usa MFA
- Monitora e blocca traffico verso rsh.sys-stat[.]download
- Implementa regole di firewall per limitare l'accesso a dispositivi IoT
- Esegui scansione regolare per rilevare rootkit e malware
- Configura backup regolari e test di recupero
- Rivedi configurazione di log e gestione delle credenziali
Sistemi e prodotti interessati
- Dispositivi IoT non protetti
- Sistemi Linux esposti a Internet
Cosa cercare (rilevamento)
- Rilevamento di file sospetti come openssh-8.0p1.tgz
- Cerca log di accessi SSH anomali o tentativi di brute force
- Monitora l'invio di dati sensibili a dotsysadmin[@]protonmail[.]com
- Verifica la presenza di rootkit come Diamorphine e Reptile
- Controlla modifiche al file authorized_keys
- Rileva l'uso di logtamper per manipolare i log
Estratto della fonte usato dal modello
Cyberattacker techniques, tools, and infrastructure Microsoft Defender for Endpoint Microsoft Defender for IoT Cryptojacking, the illicit use of computing resources to mine cryptocurrency, has become increasingly prevalent in recent years, with attackers building a cybercriminal economy around attack tools, infrastructure, and services to generate revenue from targeting a wide range of vulnerable systems, including Internet of Things (IoT) devices. Microsoft researchers have recently discovered an attack leveraging custom and open-source tools to target internet-facing Linux-based systems and IoT devices. The attack uses a patched version of OpenSSH to take control of impacted devices and install cryptomining malware. Utilizing an established criminal infrastructure that has incorporated the use of a Southeast Asian financial institution’s subdomain as a command and control (C2) server, the threat actors behind the attack use a backdoor that deploys a wide array of tools and components such as rootkits and an IRC bot to steal device resources for mining operations. The backdoor also installs a patched version of OpenSSH on affected devices, allowing threat actors to hijack SSH credentials, move laterally within the network, and conceal malicious SSH connections. The complexity and scope of this attack are indicative of the efforts attackers make to evade detection. In this blog post, we present our analysis of the tools and techniques used in this attack and the efforts made
Potential operational benefits
- Riduzione della superficie esposta a attacchi
- Miglioramento della rilevazione e risposta agli incidenti
- Minimizzazione del rischio di minacce persistenti
- Aumento della conformità alle normative di sicurezza
Text acquired from the source
Evento MISP pubblicato con TLP:CLEAR: IoT devices and Linux-based systems targeted by OpenSSH trojan campaign.
- Source
- MISP EudorIA
- Publishing entity
- MISP EudorIA
- Entity type
- Intelligence community
- Area
- Global
- Original language
- it · translation not needed
- Publication
- 30/07/2026 02:49
- Sharing
- TLP:CLEAR
- Indicators reported by the source
- 95
- IOCs indexed for lookup
- 0 values within the retention period
- IOCs available in the STIX feed
- 93Last sharing verification: 2026-09-26T05:00:59.865593+00:00
- MISP event
- 0ee609d4-c99f-428c-a7f3-0afa7efe01b6
- MITRE ATT&CK
- T1190, T1077, T1078, T1079, T1080, T1081, T1486, T1059
- Classification
- High