Bleepingcomputer
SSHStalker Botnet Infects 7,000 Linux Systems Using IRC and SSH
First seen 11 Feb 2026, 07:38 UTC
•



+5
•79% similarity
•36.4
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The SSHStalker botnet has been identified as targeting approximately 7,000 Linux systems across the United States, Europe, and Asia-Pacific. Utilizing a combination of Internet Relay Chat (IRC) and SSH for command-and-control operations, this botnet employs mass-compromise techniques to deploy various scanners and malware. The operation leverages outdated communication protocols alongside modern automation methods.
ThreatCluster AI
Timeline
2026-02-09
Flare's research team publishes findings on SSHStalker
2026-02-10
Bleepingcomputer and Scmagazine report on SSHStalker