news.mlab.sh
Back to the feed
threat-intel

22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th)

High
Image: SANS Internet Storm Center
Summary

A threat actor successfully exploited a vulnerable SSH honeypot within 22 seconds, injecting a backdoor SSH key, changing the root password, and clearing host-based access restrictions. This rapid post-exploitation sequence, part of the ongoing ‘mdrfckr’ SSH campaign, demonstrates a highly automated attack that bypasses human response. The campaign has been active for weeks, with 93 overlapping IPs continuing to scan for vulnerable systems. The attacker leveraged a weak password (root / Aa123123123) and consistently used a pre-scripted playbook, highlighting the ease with which automated attacks can compromise internet-exposed Linux systems. Defenders should prioritize disabling password authentication, implementing rate limiting, and continuously monitoring authentication logs.

Read the full article at SANS Internet Storm Center

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.