New Linux Malware Combines Mirai Botnet with Fileless Cryptominer

New Linux Malware Combines Mirai Botnet with Fileless Cryptominer

First seen 4 Dec 2025, 18:40 UTC ThecyberexpressScworld 89% similarity 62.0

Article Content

Browse articles
ThreatCluster

Researchers have identified a new Linux malware that merges the Mirai botnet's DDoS capabilities with a fileless cryptominer. This sophisticated threat employs advanced techniques such as raw-socket scanning and dynamic DNS resolution to evade detection, enabling both network disruption and financial gain. The malware utilizes a multi-stage infection chain, starting with a downloader for Mirai.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story