Linux Rabbit is a Linux-based cryptomining malware associated with a 2018 campaign targeting Linux servers and Internet-of-Things devices. Its primary objective is to compromise exposed systems and install Monero mining payloads, using architecture-specific miners depending on the victim environment. Reported targeting included systems in Russia, South Korea, the United Kingdom, and the United States.
The malware performs internet-wide target selection and SSH-based intrusion activity. It checks whether SSH is reachable on port 22, gathers basic host information such as hostname and top-level domain, applies geolocation and domain-based filtering, and then attempts authentication with a hard-coded credential list. It acquires valid SSH access through brute force and uses that access to install its payloads. Linux Rabbit also includes checks intended to avoid honeypots.
For persistence, Linux Rabbit modifies shell startup and boot-related mechanisms, including .bashrc and rc.local, allowing the miner deployment to survive reboots or user sessions. It communicates with command-and-control infrastructure through Tor-related mechanisms, using hidden services and gateways to derive active control endpoints and retrieve encoded payload locations. The malware can also update itself through GitHub.
Post-compromise, Linux Rabbit deploys cryptocurrency miners tailored to system architecture, including CNRig on x86 systems and CoinHive-related mining components on ARM and MIPS devices. On compromised web servers, it has also been observed injecting browser-based mining scripts into HTML content to monetize visitor traffic. In addition, it removes competing cryptocurrency miners from infected hosts and contains a built-in killswitch.
Linux Rabbit is closely associated with the related malware Rabbot, which shares the same code base but adds self-propagating worm behavior and exploitation of known vulnerabilities against IoT targets. The operators behind Linux Rabbit have not been publicly identified with high confidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
"actors leverage legitimate credentials to log into external remote services"; "used legitimate credentials to gain initial access, maintain access, and exfiltrate data"; "used valid accounts for initial access and privilege escalation"
“check to see if an SSH server is listening on Port 22. The malware will open a socket to see if it receives a response…”
Sandworm Team installed a modified Dropbear SSH client as a backdoor; Sandworm used Dropbear SSH with a hardcoded backdoor password to maintain persistence; Linux Rabbit attempts to gain access via SSH; Mafalda can establish an SSH connection from a compromised host to a server; Sea Turtle used external-facing SSH for initial access.
“Establish a connection to the Command and Control (C2) server using Tor gateways… it utilizes Tor hidden services to act as contact points to access a Tor gateway… establish an active C2 URL. The payload… is then sent… as an encoded URL parameter.”
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an example of malware using .bashrc for persistence.
Linux malware used to compromise Linux servers (in specified geolocations) via SSH brute forcing, establish persistence (rc.local/.bashrc), communicate with C2 via Tor hidden services/gateways, and deploy Monero mining payloads (CNRig on x86; CoinHive on ARM/MIPS). It can also inject CoinHive scripts into HTML on infected web servers, remove competing miners, update via GitHub, and includes a killswitch.
Linux malware that brute-forces SSH credentials to gain access to servers and install itself.
Linux malware that brute-forces SSH to obtain valid accounts for access/propagation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.