s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

OTX-69de00c30406a5cbb6ba9eef info

📛 Threat Title

Q1 2026 Malware Statistics Report for Linux SSH Servers

Category: shellbot Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

Analysis of attacks against Linux SSH servers during Q1 2026 reveals P2PInfect worm as the dominant threat, representing 70.3% of all attack sources. DDoS botnets including Mirai, XMRig, Prometei, and CoinMiner were identified as primary threats. A notable campaign involved installing V2Ray proxy tools on compromised systems, attributed to a suspected Chinese threat actor. Attackers employed SSH brute-force techniques to gain access, executed reconnaissance commands to assess system information, and deployed V2Ray for proxy node operations. The campaign targeted poorly secured SSH servers with weak credentials, emphasizing the need for strong password policies, access controls, and network monitoring to detect unusual outbound connections and proxy-related activities. Pulse contains 1 indicator(s) (IOCs). View on OTX to inspect.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_md5 bc72ff889e2b2a92834d5d88a97236e5

IOC database

Type
hash_md5
Value
bc72ff889e2b2a92834d5d88a97236e5
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • reference AlienVaulkt OTX
  • OTX pulse AlienVaulkt OTX

    Analysis of attacks against Linux SSH servers during Q1 2026 reveals P2PInfect worm as the dominant threat, representing 70.3% of all attack sources. DDoS botnets including Mirai, XMRig, Prometei, and CoinMiner were identified as primary threats. A notable campaign involved installing V2Ray proxy tools on compromised systems, attributed to a suspected Chinese threat actor. Attackers employed SSH brute-force techniques to gain access, executed reconnaissance commands to assess system information,

Remediations (8)

  • web:app.stationx.net

    Discover 60+ malware statistics for 2026 — malware volume, mobile threats, cryptojacking, detection rates, and AI evasion from 20+ sources.

  • web:asec.ahnlab.com

    ASEC analyzed the statistics of attacks against Linux SSH servers in Q1 2026 based on honeypot logs. The P2PInfect worm dominated, accounting for 70.3% of all attack sources, and DDoS bots such as Mirai, XMRig, Prometei, and CoinMiner were identified as the main threats. Purpose and Scope.

  • web:asec.ahnlab.com

    Statistics Report on Malware Targeting Windows Database Servers in Q1 2026 Description. analysis of ASEC's ASD logs for Q1 2026 showed a consistent trend of attacks against MS-SQL and MySQL. the number of attacks tended to decrease temporarily in February before increasing again in March.

  • web:commandlinux.com

    Linux malware detections account for only 1.3% of all operating system-targeted malware despite the platform powering critical infrastructure worldwide. This metric requires context, as attacks on Linux servers through SSH brute force, webshells, and cryptominers increased significantly.

  • web:gitnux.org

    Malware remains a massive and costly global threat despite slight declines.

  • web:securelist.com

    During Q1 2026 , the exploit kits leveraged by threat actors to target user systems expanded once again, incorporating new exploits for the Microsoft Office platform, as well as Windows and Linux operating systems. In this report , we dive into the statistics on published vulnerabilities and exploits, as well as the known vulnerabilities leveraged by popular C2 frameworks throughout Q1 2026 ...

  • web:securitricks.com

    Description Analysis of attacks against Linux SSH servers during Q1 2026 reveals P2PInfect worm as the dominant threat, representing 70.3% of all attack sources. DDoS botnets including Mirai, XMRig, Prometei, and CoinMiner were identified as primary threats.

  • web:worldmetrics.org

    Our in-depth market data report on Malware . Explore verified statistics and the latest research.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.