Outlaw, also known as Dota and sometimes Shellbot, is a long-running Linux-focused cryptomining botnet and malware package centered on unauthorized Monero mining, SSH-based propagation, and IRC-backed remote control. It is commonly described as Perl-based because its backdoor component is an obfuscated Perl IRC bot, but operational deployments are multi-stage and include shell scripts, brute-force tooling, persistence scripts, and modified XMRig miner binaries.
Outlaw primarily compromises Linux systems exposed over SSH by abusing weak or default credentials and conducting large-scale brute-force activity. Observed tradecraft includes reconnaissance of SSH-exposed hosts, automated credential attacks, and subsequent installation of attacker-controlled SSH keys for durable access. Persistence commonly relies on manipulation of authorized_keys, cron jobs, hidden working directories, watchdog scripts, and in some variants immutable file attributes to hinder remediation. Compromised hosts are also used to propagate further through SSH, giving the malware worm-like characteristics across reachable Linux environments.
The malware package typically deploys multiple functional components. Mining is performed by maliciously modified XMRig binaries configured for CPU-focused Monero mining. A backdoor component, often referred to as a stealth shellbot, connects to IRC command-and-control infrastructure and supports remote command execution, file transfer, scanning, and distributed denial-of-service activity. Additional brute-force modules have been observed performing multi-threaded SSH password attacks, changing victim credentials, collecting host information, and exfiltrating reconnaissance results to attacker-controlled infrastructure.
Outlaw also exhibits defense-evasion and competitive cryptojacking behavior. Variants kill rival miners and related processes, replace or lock SSH configuration artifacts, use obfuscation such as Base64 encoding, Perl obfuscation, shell-script compilation, and UPX packing, and may disguise malicious processes as legitimate system activity. Some campaigns have shown direct human operator interaction after initial compromise, indicating that automated propagation can be followed by manual post-exploitation.
Victimology is broad and opportunistic, with infections observed globally across Linux servers and other Unix-like systems, including environments where SSH is exposed and poorly hardened. Public reporting has linked Outlaw activity to a threat cluster first documented in 2018 and to recurring campaigns that continue to evolve their tooling while preserving recognizable SSH persistence patterns and cryptomining-focused monetization.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed artificial intelligence (AI) application endpoints for obtaining initial access to enterprise networks.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
According to this article, this apparently belong to the "Outlaw Hacking Group" which was first identified by TrendMicro in 2018.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Following successful SSH brute-force authentication, the malware replaces the existing SSH authorized_keys file with a new version containing a malicious SSH public key... The malware then changes the user credentials for the authenticated account by entering a new password using the passwd utility.
In both scripts, the malware installs cron jobs that execute its binaries at regular intervals and on system reboots.
In both scripts, the malware installs cron jobs that execute its binaries at regular intervals and on system reboots.
Following successful SSH brute-force authentication, the malware replaces the existing SSH authorized_keys file with a new version containing a malicious SSH public key... The malware then changes the user credentials for the authenticated account by entering a new password using the passwd utility.
In both scripts, the malware installs cron jobs that execute its binaries at regular intervals and on system reboots.
Following successful SSH brute-force authentication, the malware replaces the existing SSH authorized_keys file with a new version containing a malicious SSH public key... The malware then changes the user credentials for the authenticated account by entering a new password using the passwd utility.
These init scripts all use variable-based string concatenation obfuscation... The run script contains three base64-encoded blobs... obfuscated perl scripts are identified... Additionally, the malware's binaries are packed with UPX.
Another file from the hidden directory, a/kswapd0, is an ELF packed using UPX...
For persistence purposes, the attackers used the following command to wipe the existing SSH setup... cd ~ && rm -rf .ssh && mkdir .ssh ...
Following successful SSH brute-force authentication, the malware replaces the existing SSH authorized_keys file with a new version containing a malicious SSH public key... The malware then changes the user credentials for the authenticated account by entering a new password using the passwd utility.
Below are the Outlaw TTPs identified from our malware analysis... Discovery System Owner/User Discovery T1033
The malware scans the local subnet of newly compromised systems, identifying additional SSH-accessible machines to attack.
Below are the Outlaw TTPs identified from our malware analysis... Discovery System Network Connections Discovery T1049
The attacker immediately performed basic reconnaissance by running the w command to check who was logged in and then executing ps to see what processes were running.
This Perl script is an IRC-based botnet client... By default, it connects to a hardcoded IRC server over port 443 using randomly generated nicknames, joining predefined channels to await commands...
STEALTH SHELLBOT for remote control via IRC C2... SHELLBOT scripts operate as IRC-based backdoors, allowing attackers to remotely control infected machines via predefined commands sent through an IRC channel.
The malware ensures dominance by killing competing brute-forcers and miners... the run script will start the stop script, which is a typical script that bring down the defenses of any known miner configurations any known miner configurations and kill any known miner processes
53 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a competing cryptomining malware family whose processes are terminated by lambsys.
Related Reading Understanding Outlaw Linux Malware: Defend Against Botnet Threats
A rival Linux cryptomining family referenced via process and artifact names that lambsys targets for removal during infection.
Linux botnet/backdoor that compromises exposed SSH services, installs persistence by replacing or creating ~/.ssh/authorized_keys with an attacker-controlled public key tagged "mdrfckr", and uses infected hosts to scan for and compromise additional systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.