Hackers have infected Linux SSH servers with the Tsunami botnet malware.
An unknown threat actor is brute-forcing Linux SSH servers to install a wide range of malware, including the Tsunami DDoS (distributed denial of service) bot, ShellBot, log cleaners, privilege escalation tools, and an XMRig (Monero) coin miner.
See also: Manchester University: Hackers threaten data leak

SSH (Secure Shell Socket) is an encrypted network communication protocol for connecting to remote machines, supporting tunneling, TCP port forwarding, file transfer, etc.
Network administrators commonly use SSH to remotely manage Linux devices, performing tasks such as running commands, changing settings, updating software, and troubleshooting.
However, if these servers are inadequately secured, they may be vulnerable to brute-force attacks, allowing threat actors to try many possible username-password combinations until a combination is found.
See also: Elon Mode: Discovered by Tesla hacker for hands-free Full Self-Driving
Tsunami on SSH server
AhnLab's Security Emergency Response Center (ASEC) recently discovered a campaign of this type, which had compromised Linux to launch DDoS attacks and mine the Monero cryptocurrency.
The attackers scanned the Internet for publicly exposed Linux SSH servers and then attempted to brute-force the username-password pairs to connect to the server.
Once they were established on the endpoint as an administrator user, they ran the following command to extract and execute a malware collection via a Bash script.

ASE noticed that the attackers had also generated a new public and private SSH key pair for the compromised server, in order to maintain access even if the user's password changed.
Malware downloaded to infected computers includes DDoS botnets, log cleaners, cryptocurrency miners, and privilege escalation tools.
Starting with ShellBot, this Perl-based DDoS bot uses the IRC protocol for communications. It supports port scanning, HTTP flood attacks, TCP and HTTP, and can also create a reverse shell.
The other DDoS botnet malware seen in these attacks is Tsunami, which also uses the IRC protocol for communication.
The specific version ASEC is seeing is “Ziggy,” a variant of Kaiten. Tsunami persists across reboots by writing to “/etc/rc.local” and using typical system process names to hide itself.

In addition to SYN, ACK, UDP, and random flood DDoS attacks, Tsunami also supports an extensive set of remote control commands, including executing shell commands, reverse shells, gathering system information, updating itself, and receiving additional payloads from an external source.

Next up are MIG Logcleaner v2.0 and Shadow Log Cleaner. Both tools are used to eliminate evidence of intrusion on infected computers, making it less likely for victims to quickly realize the infection.
These tools support specific command line arguments that allow operators to delete, modify, or add new log files to the system.
The malware used in these attacks to achieve privilege escalation is an ELF (Executable and Linkable Format) file, which elevates the attacker's privileges to those of a root user.
Finally, threat actors activate an XMRig coin miner to take over the server's computing resources, mining Monero in a designated pool.
To defend against these attacks, Linux users should use strong account passwords or, for even greater security, require SSH keys to connect to the SSH server.
Additionally, disable root login via SSH, limit the range of IP addresses allowed to access the server, and change the default SSH port to something atypical that automated bots and infection scripts will miss.
Information source: bleepingcomputer.com
