Security researchers have analyzed an “auto-propagating” cryptocurrency mining botnet named Outlaw (also known as Dota) that targets SSH servers with weak credentials.

“Outlaw is a Linux malware that relies on SSH brute-force attacks and cryptocurrency mining and spreads like a worm. The malware’s goal is to infect and maintain control of target systems,” said Elastic Security Labs.
See also: Crocodilus malware gains access to users' crypto wallets
Outlaw is the name given to the malware’s operators. They are believed to be of Romanian origin. The group has been active since at least late 2018. The hackers have been performing brute-force attacks on SSH servers and have used the access to perform reconnaissance and maintain persistence on compromised computers, adding their own SSH keys to the “authorized_keys” file.
The attackers also incorporate a multi-stage infection process that involves using a dropper shell script (“tddwrt7s.sh”) to download an archive file (“dota3.tar.gz”), which is unpacked to launch a miner. The hackers also remove traces of previous breaches and disrupt the operation of both competing and their own older miners.
See also: New RESURGE malware exploits Ivanti vulnerability
A notable feature of the Outlaw malware is an initial access component (also known as BLITZ) that allows for self-propagationby scanning for vulnerable systems running an SSH service. The brute-force module is configured to retrieve a list of targets from an SSH command and control (C2) server to further perpetuate the cycle.
“Outlaw remains active despite the use of basic techniques such as brute-forcing SSH, SSH key manipulation, and cron-based persistence,” Elastic said. “The malware deploys modified XMRig miners, leverages IRC for C2, and includes publicly available scripts for persistence and defense.”
See also: CoffeeLoader malware: Learn everything about the new threat

Malware protection
- Update your operating system & applications – Updates include fixes for security vulnerabilities.
- Use strong and unique passwords – If one account is compromised, the rest will remain secure.
- Use two-factor authentication (2FA) – It offers extra protection for your accounts.
- Use reliable antivirus/antimalware – Enable real-time protection.
- Avoid suspicious emails and links – Phishing attacks attempt to steal personal data.
- Avoid downloading files from unknown sources – Prefer official app stores and websites.
- Enable the firewall – It can prevent unwanted network traffic.
- Use a VPN on public Wi-Fi – Protects your data from man-in-the-middle attacks.
- Don't ignore security warnings – If a program or system warns of a potential risk, investigate it before proceeding.
Source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
