Friday, May 23, 2025
HomeBotnetPyCryptoMiner - A New Linux Crypto-miner Botnet Spreading over the SSH Protocol...

PyCryptoMiner – A New Linux Crypto-miner Botnet Spreading over the SSH Protocol to Mining Monero

Published on

SIEM as a Service

Follow Us on Google News

Highly Sophisticated Python Script Based Linux Crypto-miner botnet called PyCryptoMiner abusing SSH port and targeting Linux users to mining Monero CryptoCurrency.

Its written in python language which is difficult to detect and this botnet crypto-miner uses over 36,000 domains that is related to scams, gambling, and adult services.

This Crypto miner mainly focusing on mining Monero and till December researchers estimated that it has made approximately US $46,000 mining Monero.

- Advertisement - Google News

If original command and control server become unreachable then it leverages Pastebin.com/WHATHAPPEN to receive C&C Server Assignment.

Current crypto mining malware is mainly using scripts which are very obfuscated, easily evade the detection and also very difficult to detect by nature.

Also Read: Chrome Extension Caught Silently Mining CryptoCurrency without Users Knowledge

How does this Linux Crypto-miner Works

This Crypt-miner botnet using brute forcing attack to guess SHH login credentials of the Linux machine.

Before connected it to command and control server it deploys the base64-encoded spearhead Python script and executing Obfuscated spearhead Python script.

Most of the cases malware hardcoded with the command & control server, so once it’s taken down it won’t be get connected to another C&C server.

But here attacker using Pastebin.com as an alternative one if original C&C sever goes down.

According to F5 Networks, Being exposed as a public Pastebin.com resource allowed us also to discover more information about this operation. It seems to have been running since at least August of this year because the username “WHATHAPPEN” created the resource on Aug. 21, 2017.

This pastbin.com resource is continuously accessing when original C&C Server goes down and this resource had been viewed 177,987 times.

Its execution flow starts by executing the spearhead Python script it leads to fetching base64-encoded Python script and executed from the C&C server.

It will be the main controller of the of the infected machine which is act as a botnet and The original spearhead bash script named httpsd includes a base64-encoded Python one-liner that runs every 6 hours.

its used to collect  Host/DNS name, OS name and its architecture, Number of CPUs, CPU usage once its take over the target machine.

Discovered  2 pool address which is used by this botnet were paid approximately 94 and 64 Monero which is around  $60,000 USD.

IOCs

Hash

d47d2aa3c640e1563ba294a140ab3ccd22f987d5c5794c223ca8557b68c25e0d

C&C

hxxp://pastebin.com/raw/yDnzKz72

hxxp://pastebin.com/raw/rWjyEGDq

hxxp://k.zsw8.cc:8080 (104.223.37.150)

hxxp://i.zsw8.cc:8080 (103.96.75.115)

hxxp://208.92.90.51

hxxp://208.92.90.51:443

hxxp://104.223.37.150:8090

Infected Machine

/tmp/VWTFEdbwdaEjduiWar3adW

/bin/httpsd

/bin/wipefs

/bin/wipefse

/bin/minerd

/bin/webnode

/bin/safenode

/tmp/tmplog

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Global Crackdown Nets 270 Dark Web Vendors in Major Arrests

A sweeping international crackdown, codenamed Operation RapTor, has dealt a significant blow to the...

CISA Alerts on Threat Actors Targeting Commvault Azure App to Steal Secrets

On May 22, 2025, Commvault, a leading enterprise data backup provider, issued an urgent...

CefSharp Enumeration Tool Identifies Critical Security Issues in .NET Desktop Applications

Cybersecurity researchers and red teamers, a newly released tool named CefEnum is shedding light...

Russian Hackers Exploit Oracle Cloud Infrastructure to Target Scaleway Object Storage

Russian threat actors have been leveraging trusted cloud infrastructure platforms like Oracle Cloud Infrastructure...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

New HTTPBot Botnet Rapidly Expands to Target Windows Machines

The HTTPBot Botnet, a novel Trojan developed in the Go programming language, has seen...

20-Year-Old Proxy Botnet Network Dismantled After Exploiting 1,000 Unpatched Devices Each Week

A 20-year-old criminal proxy network has been disrupted through a joint operation involving Lumen’s...

Mirai Botnet Actively Targeting GeoVision IoT Devices for Command Injection Exploits

The Akamai Security Intelligence and Response Team (SIRT) has identified active exploitation of command...