ESET detailed Linux/Shishiga, a Lua-based malware family targeting GNU/Linux systems across IoT-focused architectures including MIPS, ARM, i686, and PowerPC. The malware spreads by brute-forcing weak Telnet and SSH credentials and differs from many Linux worms by combining BitTorrent, SSH, Telnet, and HTTP for propagation and command-and-control activity. Researchers said the malware is packed with UPX, statically linked with the Lua runtime, and can deploy a main loader with the .lm extension alongside a backdoor with the .dm extension that listens on TCP port 2015.
Shishiga’s modules support credential theft, architecture detection, persistence, scanning, file upload, and retrieval of updates and scripts through BitTorrent-delivered .bt files. Infected systems may also expose an HTTP service on port 8888, with the unusual response HTTP/1.0 404 OK on the root path serving as an indicator of compromise. ESET identified 93.117.137.35 as a command-and-control server, while Censys found roughly 10 Internet-facing IPs matching the malware’s HTTP fingerprint, indicating a limited but active infection set and a malware project still under active development.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
ESET identified the malware's command-and-control server as 93.117.137.35, and Censys found about 10 Internet-facing IP addresses matching Shishiga's distinctive HTTP fingerprint. This indicated a limited but active set of infected hosts at the time of analysis.
ESET analyzed a newly identified Lua-based malware family targeting GNU/Linux systems and named it Linux/Shishiga. The malware spreads by brute-forcing weak Telnet and SSH credentials, uses BitTorrent alongside SSH, Telnet, and HTTP, and targets architectures common in IoT devices.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 37 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.