SSHStalker is a Linux botnet that automates mass compromise of internet-exposed servers over SSH and uses Internet Relay Chat (IRC) for command-and-control. It was identified in early 2026 and is characterized as a scale-first operation that prioritizes reliability, low cost, and rapid propagation over stealth. Observed victimology indicates a strong concentration on cloud-hosted Linux systems, with compromises driven primarily by weak, reused, or default SSH credentials rather than novel exploitation.
After obtaining access, SSHStalker installs persistent access mechanisms, including dropping an SSH key and establishing watchdog-style persistence through cron so the malware is relaunched quickly if interrupted. Infections have been observed restoring control within roughly a minute after process termination. The botnet also turns newly compromised hosts into scanners, rapidly probing additional systems on TCP port 22 to expand the botnet in a worm-like fashion. Its deployment chain includes staged payload delivery, on-host compilation of components, and use of multiple IRC bot variants and helper scripts.
The toolkit associated with SSHStalker includes defense-evasion features such as log-cleaning utilities that tamper with shell history and login-accounting artifacts. Reporting also links the botnet to legacy Linux privilege-escalation tooling aimed at older 2.6.x-era kernels, indicating an ability to deepen access on neglected systems. Additional associated capabilities include harvesting cloud credentials, especially AWS-related material exposed on compromised or reachable systems, and the presence of cryptomining and DDoS-enabling components, although some observations suggest operators may maintain dormant persistence before activating higher-impact functions.
Tradecraft and tooling overlap with older Outlaw/Maxlas-style Linux botnet ecosystems, but direct attribution remains unconfirmed. Romanian-language artifacts have been noted as a possible clue to operator origin, though this is not sufficient for firm attribution. Overall, SSHStalker represents a modernized revival of classic IRC-controlled Linux botnet operations, combining brute-force SSH access, rapid automated propagation, persistence, privilege-escalation tooling, and post-compromise monetization options against poorly secured Linux server fleets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“Flare’s research team has uncovered a previously undocumented Linux botnet operation we’re calling SSHStalker… SSHStalker relies on classic, “old-school” IRC botnet mechanics…”
“Flare’s research team has uncovered a previously undocumented Linux botnet operation we’re calling SSHStalker… SSHStalker relies on classic, “old-school” IRC botnet mechanics…”
“Flare’s research team has uncovered a previously undocumented Linux botnet operation we’re calling SSHStalker… SSHStalker relies on classic, “old-school” IRC botnet mechanics…”
“Flare’s research team has uncovered a previously undocumented Linux botnet operation we’re calling SSHStalker… SSHStalker relies on classic, “old-school” IRC botnet mechanics…”
“Flare’s research team has uncovered a previously undocumented Linux botnet operation we’re calling SSHStalker… SSHStalker relies on classic, “old-school” IRC botnet mechanics…”
“Flare’s research team has uncovered a previously undocumented Linux botnet operation we’re calling SSHStalker… SSHStalker relies on classic, “old-school” IRC botnet mechanics…”
“Flare’s research team has uncovered a previously undocumented Linux botnet operation we’re calling SSHStalker… SSHStalker relies on classic, “old-school” IRC botnet mechanics…”
“Flare’s research team has uncovered a previously undocumented Linux botnet operation we’re calling SSHStalker… SSHStalker relies on classic, “old-school” IRC botnet mechanics…”
“Flare’s research team has uncovered a previously undocumented Linux botnet operation we’re calling SSHStalker… SSHStalker relies on classic, “old-school” IRC botnet mechanics…”
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Flare’s research team has uncovered a previously undocumented Linux botnet operation we’re calling SSHStalker… SSHStalker relies on classic, “old-school” IRC botnet mechanics…”
“Flare’s research team has uncovered a previously undocumented Linux botnet operation we’re calling SSHStalker… SSHStalker relies on classic, “old-school” IRC botnet mechanics…”
20 distinct techniques documented for this family, organized by ATT&CK tactic.
“…persistence mechanism… using cron jobs that relaunch the malware within about a minute if disrupted… sets up persistence using cron jobs…”
“…persistence mechanism… using cron jobs that relaunch the malware within about a minute if disrupted… sets up persistence using cron jobs…”
“payloads to escalate privileges using a catalog of 15-year-old CVEs”
Security research tracking exposed Linux endpoints found that 89% of Linux endpoint attack behaviors in 2025 involved brute force or credential stuffing against SSH.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet targeting internet-exposed Linux/cloud servers via weak or default SSH credentials. After compromise it installs an SSH key for persistence/enrollment and rapidly scans for additional victims on port 22.
Linux botnet that gains initial access via automated SSH scanning and brute forcing, uses IRC-based C2, spreads in a worm-like manner by scanning from compromised hosts, and drops additional payloads for privilege escalation, AWS key harvesting, and cryptocurrency mining; uses cron-based persistence and masquerades as nmap.
Linux botnet described as using IRC-style infrastructure/communications.
SSHStalker botnet targets Linux servers with legacy exploits and SSH scanning
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.