Recently, a Linux malware downloader developed with SHC (Shell Script Compiler) was discovered and has been used to target systems with Monero miners, as well as IRC bots designed for DDoS attacks.
ASEC researchers discovered the SHC loader, which was uploaded to VirusTotal primarily by Korean users and targeted Linux-based systems in Korea.
Experts believe that these attacks are likely the result of using weak administrator account credentials to access SSH on Linux servers.
See also: MCCrash: New Windows/Linux botnet for use in DDoS attacks

See also: Hackers are cracking down on Linux devices using the PRoot tool
Hidden loading
SHC is a powerful “generic shell script compiler” for Linux that allows you to easily convert Bash shell scripts to ELF files (Linux and Unix executables).
Malicious Bash shell scripts used by threat actors typically contain system commands, which can be detected by security software installed on a Linux device.
By encoding malicious commands in SHC ELF executables with the RC4 algorithm, security software is less likely to detect them, providing cybercriminals with an opportunity to evade detection .

Drop multiple payloads
When the SHC malware downloader is executed, it will bring many other malware payloads and install them on the device.
An XMRig miner is included among the payloads and, after being downloaded from a remote URL in the form of a TAR file, will be extracted to “/usr/local/games/” before being executed.
Additionally, the file includes the “run” script and the miner configuration file for creating a specific mining pool.

XMRig, a widely abused open-source, is commonly used to extract Monero from vulnerable servers using their accessible computing power .
Integrating the configuration into the miner reduces communication between the C2 and keeps crypto mining running in the event of a hacker's server outage.
The second piece of malicious code distributed via the SHC downloader is a Pearl-based DDoS IRC bot, which is downloaded and launched on target systems.
See also: Crypto-mining malware joins forces with Chaos RAT and targets Linux
When connecting to the designated IRC server, the malware goes through a user authentication process based on the parameters set in its configuration.
If the malware is successful, it will wait for instructions from the IRC server to perform malicious activities such as TCP Flood, UDP Flood, HTTP Flooding, and port scanning. It can also perform Nmap scans, sendmail commands, and terminate processes while cleaning up log files. These are just a few of the many malicious tasks that a successful intrusion will bring about.

ASEC warns that such attacks are usually caused by the use of vulnerable passwords on exposed Linux servers.
General: Linux servers are known for their strong security features, which include built-in firewall protection as well as encryption for data storage and transmission. This means that businesses can securely store data without worrying about unauthorized access or malicious attacks. Additionally, because these features are built into Linux servers, businesses don’t need to invest in expensive security measures, such as additional firewalls or antivirus software.
Information source: bleepingcomputer.com
