Scworld
New Linux Malware Combines Mirai Botnet with Fileless Cryptominer
First seen 4 Dec 2025, 18:40 UTC
•
•89% similarity
•62.0
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Researchers have identified a new Linux malware that merges the Mirai botnet's DDoS capabilities with a fileless cryptominer. This sophisticated threat employs advanced techniques such as raw-socket scanning and dynamic DNS resolution to evade detection, enabling both network disruption and financial gain. The malware utilizes a multi-stage infection chain, starting with a downloader for Mirai.
ThreatCluster AI
How this analysis works