spirit is a Linux SSH scanning and brute-force utility used for lateral movement in intrusion and cryptomining campaigns. The provided reporting describes it as a UPX-packed binary that grabs banners from discovered hosts and brute-forces SSH logins using default credentials. It uses a credential file referred to as px, containing more than 10,000 username/password records, and is run against host lists such as h.lst to identify and compromise vulnerable systems on the same network and spread the infection.
The malware is associated in the provided content with two Linux-focused threat clusters/campaigns. In Cyble CRIL reporting on the ShadowHS intrusion chain, operators use Rustscan to identify reachable SSH endpoints and then download spirit to brute-force SSH access for lateral movement. In Aqua reporting on the 8220 gang campaign exploiting Confluence CVE-2022-26134 and misconfigured Docker environments, attackers use masscan, spirit, and px tools to scan for and brute-force SSH services within internal networks, alongside exploitation of SSH keys, to propagate across victim environments.
Observed context ties spirit to post-compromise propagation rather than initial access. It targets Linux environments and internal network hosts exposing SSH, and it has been used in campaigns focused on cloud/containerized infrastructure and cryptomining operations. Related tooling mentioned in the same campaigns includes spirit-pro and hxx as updated SSH brute-force tools, and px/pasx as credential lists. No standalone network indicators or hashes for spirit itself are explicitly provided in the content excerpt, although the reporting notes that SHA-256 hashes for spirit binaries were included in the broader IOC set.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Penetration-testing/brute-force tool used for SSH banner grabbing and credential brute forcing to enable lateral movement.
SSH brute-force and scanning tool used to propagate the attack laterally within compromised networks by attempting to gain access to additional hosts via SSH.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.