Statistical Report on Malware Targeting Linux SSH Servers in Q2 2026
Content
In the second quarter of 2026, the AhnLab SEcurity intelligence Center (ASEC) collected and analyzed attack logs targeting poorly managed Linux SSH servers through honeypots. The scope of the analysis covers attack sources that progressed to executing actual malware installation commands, as well as statistics on the malware used in those attacks.
Purpose and Scope
This report summarizes the current attack status for brute force attacks and dictionary attacks targeting Linux SSH servers, the classification of malware used in attacks, and actual attack cases. Attack types were primarily categorized as worms, CoinMiner, DDoS bots, backdoors, and Others.
Key Statistics
In the second quarter of 2026, cases were identified where XMRig was installed using a downloader and propagation malware written in the Go programming language. After a successful login, run was downloaded, followed by the execution of mysql (XMRig) and meta (propagation malware) from pack.Jpg. Meta scanned SSH ports and attempted further infections using information from the ranges and pass files.
Separately, the distribution of ShellBot under the name .B0t was confirmed, and MIG LogCleaner was also used. The compressed file auto.Jpg contained a script created with Shc (Shell Script Compiler), XHide, and XMRig. XHide is a tool that disguises process names, and Discord is an executable version of XMRig created by the threat actor.
Conclusion
Linux SSH servers continue to be Attack Targets due to weak account credentials and unpatched vulnerabilities. The report recommends using strong passwords, changing them periodically, applying the latest security patches, and implementing access control through security products such as firewalls. ASEC collects attack source addresses in real time via honeypots, and the verified attack source information is being provided through AhnLab TIP.