← Back to Feed

Case Study: Distribution of a CoinMiner Targeting Linux SSH Servers via Malware Distribution via Network Transmission

July 11, 2026 · AhnLab ASEC · Severity: HIGH

This case study from AhnLab ASEC describes the distribution of a CoinMiner targeting Linux SSH servers. The attackers use malware with propagation capabilities, including ShellBot, MIG LogCleaner, and XHide, to install the XMRig CoinMiner. The report highlights the importance of securing Linux servers against such threats.

Key Takeaways

  • Attackers target poorly managed Linux SSH servers to distribute CoinMiner malware.
  • Malware such as ShellBot, MIG LogCleaner, and XHide are used in the attack chain.
  • The XMRig CoinMiner is installed after propagation via network transmission.
☕ Buy a Coffee