MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Hackers resurrect the 90s IRC tricks with SSHStalker
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$69,465.00-1.52%
  • ethereumEthereum(ETH)$2,126.23-0.39%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$628.97-1.03%
  • rippleXRP(XRP)$1.39-2.97%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$89.29-1.12%
  • tronTRON(TRX)$0.3101421.42%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.06%
  • dogecoinDogecoin(DOGE)$0.093346-0.60%
Ethereum

Hackers resurrect the 90s IRC tricks with SSHStalker

Last updated: February 15, 2026 4:00 am
Published: 1 month ago
Share

Compilers are downloaded locally to build payloads for reliable cross-distribution execution

SSHStalker, a recently discovered Linux botnet, is apparently relying on the classic IRC (Internet Relay Chat) protocol to manage its operations.

Created in 1988, IRCwas once the dominant instant messaging system for technical communities due to its simplicity, low bandwidth needs, and cross-platform compatibility.

Unlike modern command-and-control frameworks, SSHStalker uses multiple bots, redundant channels, and servers to maintain control over infected devices while keeping operational costs low.

SSHStalker’s malware achieves initial access through automated SSH scanning and brute-force attacks, and then uses a Go-based binary disguised as the open-source network tool nmap to infiltrate servers.

Researchers from security firm Flare documented nearly 7,000 bot scan results in a single month, mainly targeting cloud infrastructure, including Oracle Cloud environments.

Once a host is compromised, it becomes part of the botnet’s propagation mechanism, scanning other servers in a worm-like pattern.

After infection, SSHStalker downloads the GCC compiler to build payloads directly on the compromised system, which ensures its C-based IRC bots can run reliably across different Linux distributions.

These bots contain hard-coded servers and channels that enroll the host into the IRC-controlled botnet.

Additional payloads named GS and bootbou provide orchestration and execution sequencing, effectively creating a scalable network of infected machines under centralized IRC control.

Persistence on each host is maintained through cron jobs set to run every minute, which monitor the main bot process and relaunch it if terminated, creating a constant feedback loop.

The botnet also leverages exploits for 16 old Linux kernel CVEs dating back to 2009 to 2010, using them to escalate privileges once a low-privileged user account is compromised.

Beyond basic control, SSHStalker has built-in monetization mechanisms, as the malware harvests AWS keys, performs website scanning, and includes cryptomining capabilities via PhoenixMiner for Ethereum mining.

Although DDoS capabilities exist, Flare has not observed any attacks, suggesting that the botnet is either in testing or hoarding access.

Defensive strategies against SSHStalker emphasize monitoring compiler installations, unusual cron activity, and IRC-style outbound connections.

Administrators are advised to disable SSH password authentication, remove compilers from production environments, and enforce strict egress filtering.

Read more on TechRadar

This news is powered by TechRadar TechRadar

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Raffles Financial Group Limited: Raffles Financial Group Ltd (RICH) and CICADA Finance Partner to Launch Raffles Crypto Treasury
Ripple News: BlackRock May File for XRP ETFs, Says NovaDius President
Ethereum (ETH) ETF Inflows Surge as Bullish Flag Pattern Emerges
Crypto Market News: Crypto Whales Move Into MoonBull for 1000X Gains – Top Crypto to Buy Today Amid LINK and BCH News – The Bit Journal
Clapp Launches Crypto Credit Line With 0% Interest on Unused Funds

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Ethereum signals shift as EF names Aue, Stańczak exits
Next Article Vitalik Buterin warns prediction markets as short-term dopamine bets hijack narrative – Cryptopolitan
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d