← Back to Feed
Case Study: Distribution of a CoinMiner Targeting Linux SSH Servers via Malware Distribution via Network Transmission
July 11, 2026 · AhnLab ASEC · Severity: HIGH
This case study from AhnLab ASEC describes the distribution of a CoinMiner targeting Linux SSH servers. The attackers use malware with propagation capabilities, including ShellBot, MIG LogCleaner, and XHide, to install the XMRig CoinMiner. The report highlights the importance of securing Linux servers against such threats.
Key Takeaways
- Attackers target poorly managed Linux SSH servers to distribute CoinMiner malware.
- Malware such as ShellBot, MIG LogCleaner, and XHide are used in the attack chain.
- The XMRig CoinMiner is installed after propagation via network transmission.