Skip to content
SSHStalker botnet targets Linux servers with legacy exploits and SSH scanning

SSHStalker botnet targets Linux servers with legacy exploits and SSH scanning

Securityaffairs.Co Pierluigi Paganini February 11, 2026

A new Linux botnet, SSHStalker, has infected 7,000 systems using old 2009-era exploits, IRC bots, and mass-scanning malware. Flare researchers uncovered a previously undocumented Linux botnet dubbed SSHStalker, observed via SSH honeypots over two months. Researchers ran an SSH honeypot with weak credentials starting in early 2026 and spotted a set of intrusions unlike […]

Extracted Entities

Attack Types (2)

Malware (1)

MITRE ATT&CK (1)

Platforms (1)