SSHStalker botnet uses old-school IRC for large-scale Linux attacks
The botnet incorporates exploits for more than a dozen Linux kernel vulnerabilities dating back to 2009–2010.
The botnet incorporates exploits for more than a dozen Linux kernel vulnerabilities dating back to 2009–2010.
In total, the researchers observed seven distinct macOS malware families installed on the victim’s system.
Malwarebytes says the campaign impersonates not only 7-Zip, but HolaVPN, TikTok, WhatsApp, and Wire VPN.
There is currently no public information detailing attacks that exploited the flaws.
The intrusion originated from a single SmarterMail VM that had been set up by an employee and was not receiving updates.
The activity may have involved recently disclosed flaws tracked as CVE-2025-40551 and CVE-2025-40536, or a previous issue (CVE-2025-26399).
The activity exploits exposed Docker APIs, Kubernetes clusters, Ray dashboards, and Redis servers, as well as the critical React2Shell vulnerability.
The flaws (CVE-2026-1281 and CVE-2026-1340) allow attackers to remotely compromise mobile device management systems without authentication.
The attackers are exploiting Signal’s legitimate features rather than malware or software vulnerabilities.
TGR-STA-1030 relies on an extensive toolkit of frameworks, web shells, tunneling utilities to maintain long-term access.
Showing elements 251 - 260