The truth behind the dangerous Rex Botnet.

The Linux-based malware Rex has not yet spread to a dangerously large number of users, nor is it as dangerous as initially thought. What has been revealed so far is that it is a malware that has managed to take control of just 150 botnets around the world.
Initially, security researchers who began analyzing it last May believed that Rex was ransomware that exploited vulnerabilities in Drupal websites, with the aim of encrypting their files and demanding a ransom for decryption.
However, a more thorough analysis, which was completed over the summer, revealed that the malware found during the initial infections on computer systems also had many different capabilities in terms of its functionality. It had the ability to perform DDoS attacks (distributed denial of service attacks), use the power of the computer systems it compromised to produce crypto-currency such as Bitcoins, BlackCoins, Dash, etc., communicate with cooperating bots via the DHT P2P protocol, but also replicate itself on any other device it had the ability to.
Security researchers report that the team behind the malware was more focused on infiltrating IT systems than creating a botnet for DDoS attacks. The attackers exploited vulnerabilities in websites based primarily on Drupal, but also on WordPress and Magento, as well as applications such as Exagrid, Apache Jetspeed, and AirOS home routers.
Of course, both the Rex malware and its functionality are evolving day by day by its creators with the aim of further spreading the virus.
