Thursday , June 11 2026
LINUX

ALERT
Hackers Using Supershell Malware Targeting Linux SSH Servers

Researchers found an attack targeting poorly secured Linux SSH servers using Supershell, a backdoor written in Go that gives attackers remote control of affected systems.

After the initial infection, attackers likely used scanners to find more vulnerable targets and launched dictionary attacks with credentials collected from the compromised systems.

South Korea fines Coupang Record $409 mln fine for data leak

South Korea's privacy regulator said on Thursday (June 11) that the country will fine e-commerce giant Coupang 625 billion won...
Read More
South Korea fines Coupang Record $409 mln fine for data leak

ShinyHunters claim stolen data from 100+ org via oracle PeopleSoft servers

Oracle PeopleSoft servers are under attack in ongoing data theft by the ShinyHunters gang, which claim to have stolen data...
Read More
ShinyHunters claim stolen data from 100+ org via oracle PeopleSoft servers

Security Update: RoguePlanet, BitLocker Bypass, Chromium Zero-Day, and More Critical Threats Uncovered

Cybersecurity experts found several serious flaws this week in Windows, Chromium, OpenSSL, Microsoft Exchange, and ServiceNow. Some of these flaws...
Read More
Security Update: RoguePlanet, BitLocker Bypass, Chromium Zero-Day, and More Critical Threats Uncovered

73 Microsoft Packages Compromised in Password Stealer Attack

GitHub disabled 73 repositories in four Microsoft groups: Azure, Azure-Samples, Microsoft, and MicrosoftDocs. Each repo now shows GitHub’s “This repository...
Read More
73 Microsoft Packages Compromised in Password Stealer Attack

New Windows Defender ‘RoguePlanet’ zero-day grants SYSTEM privileges

A security expert shared a new Microsoft Defender vulnerability called "RoguePlanet" only hours after Microsoft fixed two earlier problems in...
Read More
New Windows Defender ‘RoguePlanet’ zero-day grants SYSTEM privileges

Microsoft June Patches 200 Vulnerabilities including 3 zero days

Microsoft's June 2026 Patch Tuesday updates fix about 200 security flaws found in the company's products. None of the flaws fixed...
Read More
Microsoft June Patches 200 Vulnerabilities including 3 zero days

World’s first wind power underwater data center is now live

The first business underwater data center run by offshore wind has started working near Shanghai. Submerged 10 metres under the...
Read More
World’s first wind power underwater data center is now live

VMware Fixed Multiple Flaws Allow Attackers to Inject Malicious Scripts

Broadcom has revealed three stored cross-site scripting (XSS) flaws that affect VMware Cloud Foundation Operations and some other products. They...
Read More
VMware Fixed Multiple Flaws Allow Attackers to Inject Malicious Scripts

CVE-2026-50751
Check Point VPN 0-day Flaw Exploited in the Wild 

Check Point Research found that CVE-2026-50751, a serious flaw in Check Point Remote Access VPN and Mobile Access, is being...
Read More
CVE-2026-50751  Check Point VPN 0-day Flaw Exploited in the Wild 

AI-designed First ‘universal vaccine’ tested in humans

AI helped to make a new kind of vaccine that can protect people from many types of viruses and stop...
Read More
AI-designed First ‘universal vaccine’ tested in humans

The data shows a list of IP addresses used by threat actors along with root credentials, including common passwords such as “root/password” and “root/123456789.” Attackers often use these to access vulnerable systems.

The attacker used different methods to download and run harmful scripts after breaching a system. An attacker used wget, curl, tftp, and ftpget to download scripts from various sources, such as web servers and FTP servers, including non-standard ports.

The attacker ran downloaded scripts using shell commands, gaining remote access and possibly installing more malware. They also tried to cover their tracks by deleting the scripts and other related files.

  GitHub page of Supershell

An attacker installed the disguised Supershell backdoor on a poorly managed Linux system, allowing them remote control, as indicated by its internal strings, behavior, and logs.

The main goal appears to be taking control of the system, but the attacker might also want to install a cryptocurrency miner, like XMRig, to exploit system resources for personal gain. This fits typical attack patterns targeting weak Linux systems.

Threat actors are taking advantage of insecure Linux SSH servers by installing the Supershell backdoor, allowing remote control of affected systems and leading to data theft and other malicious actions.

ASEC recommends that administrators focus on strong password practices, regular updates, and effective security measures like firewalls to mitigate this threat.

Keeping V3 updated is essential to prevent malware infections. These countermeasures can greatly reduce the risk of Supershell attacks for organizations.

The detected malware includes a Cobalt Strike backdoor, a shell agent downloader, and an ElfMiner downloader, identified as Backdoor/Linux.CobaltStrike.3753120, likely used for remote access and control.

The Downloader/Shell.Agent.SC203780 is a malicious shell agent that downloads and runs other harmful software. The ElfMiner downloader, Downloader/Shell.ElfMiner.S1705, was likely used to install cryptocurrency mining malware.

Check Also

Check Point

CVE-2026-50751
Check Point VPN 0-day Flaw Exploited in the Wild 

Check Point Research found that CVE-2026-50751, a serious flaw in Check Point Remote Access VPN …