Monday , August 31 2026
LINUX

ALERT
Hackers Using Supershell Malware Targeting Linux SSH Servers

Researchers found an attack targeting poorly secured Linux SSH servers using Supershell, a backdoor written in Go that gives attackers remote control of affected systems.

After the initial infection, attackers likely used scanners to find more vulnerable targets and launched dictionary attacks with credentials collected from the compromised systems.

Five Critical WordPress Flaws Lead to Site Takeover or RCE

Many serious security flaws have been found in WordPress plugins and themes, such as WPMU DEV Dashboard, Avada, TranslatePress, Pods,...
Read More
Five Critical WordPress Flaws Lead to Site Takeover or RCE

700 AI agents united to hack Hugging Face after breaking isolation

700 AI agents supposedly escaped their isolation, created a secret communication channel, and worked together to attack Hugging Face's systems....
Read More
700 AI agents united to hack Hugging Face after breaking isolation

ServiceNow warns of three critical security vulnerabilities

ServiceNow issued security updates for three new serious AI Platform problems that can be used in code injection, SQL injection,...
Read More
ServiceNow warns of three critical security vulnerabilities

100+ Tech and Security Orgs Urge Global Cyber Defense Boost Against AI Threats

Over 100 tech, cybersecurity, and finance groups have signed an open letter with OpenAI. They want a global increase in...
Read More
100+ Tech and Security Orgs Urge Global Cyber Defense Boost Against AI Threats

8.7 Million Customers data exposed from 3 Airports 

3 airports in the UK were affected by a "cyber security incident." Hackers got into data belonging to nearly nine...
Read More
8.7 Million Customers data exposed from 3 Airports 

Crack 85 Accounts and Steal 2,500+ Records
8-Agent AI Framework Used to Compromise Gov’t Entities in Asia

A cyberattack using open-source AI tools almost ran on its own. It affected government systems in Asia, compromised into 85...
Read More
Crack 85 Accounts and Steal 2,500+ Records  8-Agent AI Framework Used to Compromise Gov’t Entities in Asia

270+ Zimbra servers compromised in continuous attacks

Threat actors have already compromised more than 270 Zimbra instances in attacks that let them run code remotely. These attacks...
Read More
270+ Zimbra servers compromised in continuous attacks

Singapore Approves 200MW Data-Centre Expansion Under Second Call

Singapore has picked four data-centre plans for a total of 200MW of power in its second Data Centre Call for...
Read More
Singapore Approves 200MW Data-Centre Expansion Under Second Call

Chameleon SEO Poisoning
Hackers poison Bing and Google search results to deliver phishing banking pages

Bank customers looking for a login page can now fall into a trap before getting a strange email or text....
Read More
Chameleon SEO Poisoning  Hackers poison Bing and Google search results to deliver phishing banking pages

Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

A mysterious AI model dubbed "Ox Alpha" has surfaced online and created noise within the developer community after releasing on...
Read More
Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

The data shows a list of IP addresses used by threat actors along with root credentials, including common passwords such as “root/password” and “root/123456789.” Attackers often use these to access vulnerable systems.

The attacker used different methods to download and run harmful scripts after breaching a system. An attacker used wget, curl, tftp, and ftpget to download scripts from various sources, such as web servers and FTP servers, including non-standard ports.

The attacker ran downloaded scripts using shell commands, gaining remote access and possibly installing more malware. They also tried to cover their tracks by deleting the scripts and other related files.

  GitHub page of Supershell

An attacker installed the disguised Supershell backdoor on a poorly managed Linux system, allowing them remote control, as indicated by its internal strings, behavior, and logs.

The main goal appears to be taking control of the system, but the attacker might also want to install a cryptocurrency miner, like XMRig, to exploit system resources for personal gain. This fits typical attack patterns targeting weak Linux systems.

Threat actors are taking advantage of insecure Linux SSH servers by installing the Supershell backdoor, allowing remote control of affected systems and leading to data theft and other malicious actions.

ASEC recommends that administrators focus on strong password practices, regular updates, and effective security measures like firewalls to mitigate this threat.

Keeping V3 updated is essential to prevent malware infections. These countermeasures can greatly reduce the risk of Supershell attacks for organizations.

The detected malware includes a Cobalt Strike backdoor, a shell agent downloader, and an ElfMiner downloader, identified as Backdoor/Linux.CobaltStrike.3753120, likely used for remote access and control.

The Downloader/Shell.Agent.SC203780 is a malicious shell agent that downloads and runs other harmful software. The ElfMiner downloader, Downloader/Shell.ElfMiner.S1705, was likely used to install cryptocurrency mining malware.

Check Also

270 Zimbra

270+ Zimbra servers compromised in continuous attacks

Threat actors have already compromised more than 270 Zimbra instances in attacks that let them …