Comment on Powerful Malware Disguised as Crypto Miner Infects 1M+ Windows, Linux PCs

<- View Parent
Eyron@lemmy.world ⁨11⁩ ⁨months⁩ ago

They describe an SSH infector, as well as a credentials scanner. To me, that sounds like it started like from exploited/infected Windows computers with SSH access, and then continued from there.

With how many unencrypted SSH keys there are, how most hosts keep a list of the servers they SSH into, and how they can probably bypass some firewall protections once they’re inside the network: not a bad idea.

source
Sort:hotnewtop