A honeypot recently uncovered a spam campaign that uses compromised devices to attack vulnerable servers. Since hackers exploit devices that typically have weak credentials, they use them as proxies to push a PHP script to the server. This script then sends emails containing links to sites that are essentially “traps.”

Most of the samples detected were for spam emails and redirecting users to such scam sites. However, the processes executed by botnets could also be used to spread malware. At the same time, the use of a PHP script not only allows the system to be infected, but also allows the hacker to regain access to the servers even after the vulnerability is fixed.
What is certain is that these hackers knew very well what they were doing. By using compromised devices, they make the job of security, which is none other than detecting the perpetrator of the attack, more difficult.
It is quite possible that they chose these devices to send the emails to after scanning for open SSH ports. Also, these scam sites imitate legitimate sites and cryptocurrency. They do this well enough to deceive potential victim users who are either not cautious enough or, for example, want to earn extra income.

The fact that so many people are being duped by these scams doesn't mean that hackers will only get financial rewards. In the future, they will be able to acquire methods to install more malware, even as IT teams patch the flaws. In practice, these devices are included in botnets or used for other such scams.
Even though many of the consequences of the attack have been resolved, the following instructions will certainly help in the future.
- Do not click on links contained in emails from unknown senders.
- Weak and short passwords should definitely be changed.
- Ports that are not used necessarily remain closed.
