Researchers reported an ongoing Linux server compromise campaign in which attackers exploit Control Web Panel (CWP) to install a malware package known as Facefish, an LD_PRELOAD-based userland rootkit that backdoors OpenSSH. The intrusion chain retrieves an installer often named sshins, downloads a first-stage payload from 176.111.174.26, drops a malicious shared library as /lib64/libs.so, adds it to /etc/ld.so.preload, restarts sshd, and then removes evidence from CWP logs and shell history. The malware primarily targets x64 Linux systems and has also shown the ability to adapt to FreeBSD environments.
Once active, the backdoor hooks OpenSSH-related functions to steal SSH credentials, collect host information, and provide remote access through arbitrary command execution and reverse shell capabilities. Researchers said the malware beacons to 176.111.174.26:443 over raw TCP and protects communications with negotiated keys and Blowfish-encrypted traffic, using techniques that hinder straightforward network detection. The samples also employ anti-analysis measures including UPX packing, erased ELF sections, and randomized rootkit encryption keys, while analysts assessed the operators were likely harvesting access and system intelligence for later monetization rather than immediately deploying follow-on payloads such as cryptominers.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
On February 1, attackers used a command injection exploit against Control Web Panel to retrieve and run an installer named sshins on Linux servers. The installer dropped /lib64/libs.so, added it to /etc/ld.so.preload, restarted sshd, and erased traces from CWP logs and shell history.
Juniper noted that the Zero Day Initiative disclosed 37 zero-day vulnerabilities affecting Control Web Panel in 2020, providing context for the product's long-running security issues.
Juniper Threat Labs published findings on a campaign hijacking Linux SSH servers through CWP exploitation and an LD_PRELOAD-based OpenSSH backdoor. Juniper also said the malware and C2 infrastructure were detected and blocked by Juniper ATP products and associated IDP signatures.
Netlab 360 published an analysis of the Facefish malware family, describing its dropper, LD_PRELOAD rootkit, OpenSSH credential theft, host reconnaissance, and Blowfish-encrypted C2 communications with 176.111.174.26:443.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.