Researchers linked multiple Linux intrusions to a Romanian-speaking threat cluster that brute-forced weak SSH credentials, compromised servers and network devices at scale, and deployed a Perl-based Shellbot with IRC command-and-control. Trend Micro found infrastructure capable of generating target lists covering roughly 80 million IP addresses, logs indicating more than 65,000 potentially compromised hosts, and tooling including the Haiduc SSH brute-forcer, process-masquerading utility Faker, privilege-escalation exploits such as CVE-2017-16995 and Dirty Cow variants, and high-availability C2 built with CARP. Bitdefender separately tied a likely Romanian group to Linux-focused scanning, SHC-obfuscated loaders, Discord webhook reporting, a customized Perl IRC bot, and a Golang SSH bruteforcer offered in a SaaS-like model, with monetization centered on Monero mining via customized XMRig payloads.
Additional reporting showed the campaign’s tradecraft remained active across traditional servers and cloud-native environments. JPCERT/CC documented attackers using stolen SSH access to move laterally, install XMRig, hide mining with XHide, tamper with logs, and continue scanning for new SSH targets, while Sysdig observed Shellbot compromise a Tomcat container through brute-forced default credentials, download multi-architecture payloads, establish persistence, erase traces, and receive commands for file transfer, port scanning, data exfiltration, and DDoS attacks. Together, the reports describe a long-running Linux-focused operation that blends brute-force access, worm-like propagation, cryptojacking, and botnet functionality across exposed infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Bitdefender began investigating the group in May 2021 after observing its cryptojacking activity using the .93joshua loader on Linux systems.
JPCERT/CC confirmed cases in February 2021 where attackers gained SSH access to publicly reachable servers, moved laterally inside intranets, and deployed the XMRig miner while hiding activity and deleting logs.
Bitdefender reported that infrastructure associated with mexalz.us had hosted malware since at least February 2021, including multiple archives, loaders, and related payloads used in the campaign.
Bitdefender said the likely Romanian threat group had been active since at least 2020, targeting Linux machines with weak SSH credentials and monetizing access primarily through Monero mining.
In the observed Sysdig case, the infected container was later used to flood a remote domain with thousands of packets after connecting to IRC-based command-and-control infrastructure.
Sysdig observed Shellbot compromise a Tomcat container after attackers brute-forced default dashboard credentials, spawned a reverse shell, and downloaded multiple scripts and binaries for persistence and control.
Trend Micro found Monero-mining payloads, a wallet holding 1.161 XMR at the time of writing, privilege-escalation exploits, process-masquerading tooling, and CARP-based high-availability command-and-control across compromised hosts.
Among the compromised hosts, Trend Micro identified a hotel firewall in South Korea with two backdoors in the root filesystem and notified the Korean CERT about the incident.
Recovered scripts generated randomized target lists totaling about 80 million IP addresses, and loot files listed 65,288 possibly compromised hosts with SSH credentials across servers, smart devices, and network equipment.
Trend Micro analyzed a compromised FTP server containing configuration files, payloads, brute-force tools, and scripts tied to a Perl-based shellbot and the Linux-focused toolkit it named Outlaw.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
sysdig.com
Open sourcebitdefender.com
Open sourceblogs.jpcert.or.jp
Open sourcedocuments.trendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.