The long-running Outlaw (also known as Dota3) Linux botnet is compromising internet-exposed systems through opportunistic SSH brute-force attacks, then spreading laterally across reachable subnets. Its payload installs a modified XMRig Monero miner, an IRC-based STEALTH SHELLBOT command-and-control component, and the BLITZ brute-forcer to locate and compromise additional Linux and potentially IoT devices.
Outlaw maintains access through cron jobs and attacker-controlled SSH authorized_keys, hides files in locations such as ~/.configrc6, obfuscates scripts, sets file immutability, and terminates competing mining malware. Honeypot observations also identified manual operator activity for reconnaissance and payload reinstallation; defenders should investigate anomalous SSH authentication attempts, unauthorized cron or SSH-key modifications, hidden or encoded scripts, socat usage, suspicious kernel tuning, mining processes, and lateral SSH brute-force traffic.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
After BLITZ brute-forced a honeypot and changed its password, an operator logged in from 212.234.225[.]29, ran w and ps reconnaissance commands, and downloaded and executed a fresh dota3.tar.gz payload using wget. The activity indicated that the otherwise automated campaign could be manually maintained after compromise.
The tddwrt7s.sh dropper downloads dota3.tar.gz, whose components establish hidden installation paths, cron-based persistence, attacker-controlled SSH keys, and a modified XMRig miner. The package also deploys STEALTH SHELLBOT for IRC command-and-control and uses socat forwarding infrastructure.
The BLITZ (also known as kthreadadd) component performs high-volume SSH scanning and password guessing, allowing newly compromised hosts to attack further SSH-accessible systems, including local-subnet targets. BLITZ can copy dota3.tar.gz directly from an infecting host to compromised systems.
OUTLAW was observed as a persistent Linux coinmining package in multiple versions over several years. It uses opportunistic SSH brute-force attempts against weak or default credentials for access.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.