PULSE NAME
Q1 2026 Malware Statistics Report for Linux SSH Servers
WHITE AlienVault 2026-04-14 Modified: 2026-04-14
2
IOCs
LOW VOLUME
Analysis of attacks against Linux SSH servers during Q1 2026 reveals P2PInfect worm as the dominant threat, representing 70.3% of all attack sources. DDoS botnets including Mirai, XMRig, Prometei, and CoinMiner were identified as primary threats. A notable campaign involved installing V2Ray proxy tools on compromised systems, attributed to a suspected Chinese threat actor. Attackers employed SSH brute-force techniques to gain access, executed reconnaissance commands to assess system information, and deployed V2Ray for proxy node operations. The campaign targeted poorly secured SSH servers with weak credentials, emphasizing the need for strong password policies, access controls, and network monitoring to detect unusual outbound connections and proxy-related activities.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
P2PInfect Mirai XMRig Prometei CoinMiner Gafgyt ShellBot Tsunami Xorddos V2Ray
Indicators of Compromise (1 / 2 total)
All FileHash-MD5 IPv4
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 bc72ff889e2b2a92834d5d88a97236e5 2026-04-14