A Linux-focused botnet used the Tor network and a large proxy infrastructure to conceal command-and-control traffic, deliver payloads, and exfiltrate victim data while deploying the XMRig Monero miner on compromised systems. The malware arrived as a multilayer-encoded shell script, supported multiple Linux architectures, and fetched legitimate utilities such as ss, ps, and curl when they were not already present, indicating an effort to operate flexibly across diverse server environments.
The campaign also abused infrastructure-as-code and cloud management tools including Ansible, Chef, and SaltStack to expand laterally and scale infections. Once active, the malware removed rival cryptominers and disabled or uninstalled cloud monitoring and security agents tied to Tencent Cloud, Alibaba Cloud, and Aegis/YunJing, while researchers found evidence suggesting some Tor proxy and mining-pool servers used in the operation may themselves have been compromised hosts with exposed and vulnerable services.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Trend Micro researchers David Fiser and Alfredo Oliveira reported a Linux-targeting botnet that used Tor-hosted payload delivery, proxy infrastructure, and infrastructure-as-code tools including Ansible, Chef, and SaltStack for propagation. The malware installed XMRig, disabled cloud security agents, and removed competing miners; the researchers said this was the first case they had observed of Linux malware abusing IaC tools to spread.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.