Outlaw, also known as Dota and Shellbot, is a long-running Linux cryptocurrency-mining botnet associated with the Outlaw Hacking Group. It opportunistically compromises systems exposed to SSH by attempting weak or default credentials, then propagates from infected hosts to additional SSH-reachable systems. Outlaw deploys a modified XMRig-based Monero miner, a Perl-based IRC backdoor commonly described as STEALTH SHELLBOT, and the BLITZ SSH scanning and brute-force component. The IRC backdoor supports remote command execution, payload management, scanning, file transfer, and DDoS functions.
Outlaw establishes persistence through cron jobs and attacker-controlled SSH authorized keys, and may alter account passwords following compromise. It uses hidden components, script and Perl obfuscation, packed binaries, immutable file attributes, watchdog processes, and termination of competing miners to resist removal and evade detection. It collects host and privilege information and sends compromised-host data to its command infrastructure. Mining routines optimize systems for RandomX workloads, while the botnet consumes victim CPU resources and uses compromised machines to continue SSH-based propagation. Activity has affected Linux servers and other SSH-accessible Linux systems worldwide.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed artificial intelligence (AI) application endpoints for obtaining initial access to enterprise networks.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
According to this article, this apparently belong to the "Outlaw Hacking Group" which was first identified by TrendMicro in 2018.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Following successful SSH brute-force authentication, the malware replaces the existing SSH authorized_keys file with a new version containing a malicious SSH public key... The malware then changes the user credentials for the authenticated account by entering a new password using the passwd utility.
In both scripts, the malware installs cron jobs that execute its binaries at regular intervals and on system reboots.
In both scripts, the malware installs cron jobs that execute its binaries at regular intervals and on system reboots.
Following successful SSH brute-force authentication, the malware replaces the existing SSH authorized_keys file with a new version containing a malicious SSH public key... The malware then changes the user credentials for the authenticated account by entering a new password using the passwd utility.
Once access is gained, it changes the user’s password for persistent access.
In both scripts, the malware installs cron jobs that execute its binaries at regular intervals and on system reboots.
Following successful SSH brute-force authentication, the malware replaces the existing SSH authorized_keys file with a new version containing a malicious SSH public key... The malware then changes the user credentials for the authenticated account by entering a new password using the passwd utility.
Once access is gained, it changes the user’s password for persistent access.
These init scripts all use variable-based string concatenation obfuscation, where commands are split into small variable fragments that are dynamically concatenated and executed.
The malware's binaries are packed with UPX, reducing their size and altering their signature to evade traditional malware detection.
Following successful SSH brute-force authentication, the malware replaces the existing SSH authorized_keys file with a new version containing a malicious SSH public key... The malware then changes the user credentials for the authenticated account by entering a new password using the passwd utility.
Once access is gained, it executes system reconnaissance commands, collecting user privileges.
The malware scans the local subnet of newly compromised systems, identifying additional SSH-accessible machines to attack.
SHELLBOT scripts operate as IRC-based backdoors, allowing attackers to remotely control infected machines via predefined commands sent through an IRC channel.
STEALTH SHELLBOT for remote control via IRC C2... SHELLBOT scripts operate as IRC-based backdoors, allowing attackers to remotely control infected machines via predefined commands sent through an IRC channel.
The malware ensures dominance by killing competing brute-forcers and miners... the run script will start the stop script, which is a typical script that bring down the defenses of any known miner configurations any known miner configurations and kill any known miner processes
53 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a competing cryptomining malware family whose processes are terminated by lambsys.
Related Reading Understanding Outlaw Linux Malware: Defend Against Botnet Threats
A rival Linux cryptomining family referenced via process and artifact names that lambsys targets for removal during infection.
Linux botnet/backdoor that compromises exposed SSH services, installs persistence by replacing or creating ~/.ssh/authorized_keys with an attacker-controlled public key tagged "mdrfckr", and uses infected hosts to scan for and compromise additional systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.