{"id":4190,"date":"2022-05-25T01:49:36","date_gmt":"2022-05-25T06:49:36","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=4190"},"modified":"2022-05-25T01:49:37","modified_gmt":"2022-05-25T06:49:37","slug":"the-xorddos-botnet-is-back-targeting-linux-again","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/the-xorddos-botnet-is-back-targeting-linux-again\/","title":{"rendered":"The XorDdos Botnet is back targeting Linux again"},"content":{"rendered":"\n<p style=\"font-size:15px;font-style:italic;font-weight:100\">A Linux botnet malware known as XorDdos has witnessed a 254% increase in activity in the last six months, according to the latest research from Microsoft.<\/p>\n\n\n\n<p style=\"font-size:15px;font-style:italic;font-weight:100\">The Trojan, named for carrying out denial-of-service attacks on Linux systems and its use of XOR-based encryption for communications with its command and control (C2) server, is known to have been active since at least 2014.<\/p>\n\n\n\n<p style=\"font-size:15px;font-style:italic;font-weight:100\">XorDdos performs automated password guessing attacks via brute force attacks on thousands of Linux servers to find matching administrator credentials used on servers with SSH. After obtaining the credentials, XorDDoS uses root privileges to install itself on the Linux system and uses XOR-type encryption to communicate with the attacker&#8217;s command and control infrastructure.<\/p>\n\n\n\n<p style=\"font-size:15px;font-style:italic;font-weight:100\">This malware is designed to support different Linux distributions, not to mention that it comes with features to siphon sensitive information, install a rootkit, and act as a vector for tracking activities.<\/p>\n\n\n\n<p style=\"font-size:15px;font-style:italic;font-weight:100\">In another sign that the malware could act as a conduit for other threats, devices that were originally breached with XorDdos are subsequently infected with another Linux Trojan called Tsunami, which then implements the XMRig coin miner.<\/p>\n\n\n\n<p style=\"font-size:15px;font-style:italic;font-weight:100\">XorDDoS was one of the most active Linux focused malware families during 2021 and has benefited from the growth of Internet of Things (IoT) devices, which mostly run on Linux variants, but has also targeted to misconfigured Docker clusters in cloud services.<\/p>\n\n\n\n<p style=\"font-size:15px;font-style:italic;font-weight:100\">As we have always said, the passwords of your accounts are the main defense against cybercriminals and that is why we must strengthen it and change it from time to time.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The XorDdos Botnet has been active since at least 2014 and today we will talk about it because it has returned and is targeting Linux systems<\/p>\n","protected":false},"author":1,"featured_media":4191,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14,10],"tags":[97,36],"class_list":["post-4190","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-botnets","category-cybersecurity","tag-botnet","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>The XorDdos Botnet is back targeting Linux again - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"The XorDdos Botnet has been active since at least 2014 and today we will talk about it because it has returned and is targeting Linux systems\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/the-xorddos-botnet-is-back-targeting-linux-again\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The XorDdos Botnet is back targeting Linux again - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"The XorDdos Botnet has been active since at least 2014 and today we will talk about it because it has returned and is targeting Linux systems\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/the-xorddos-botnet-is-back-targeting-linux-again\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2022-05-25T06:49:36+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-05-25T06:49:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/05\/Botnet.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/the-xorddos-botnet-is-back-targeting-linux-again\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/the-xorddos-botnet-is-back-targeting-linux-again\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"The XorDdos Botnet is back targeting Linux again\",\"datePublished\":\"2022-05-25T06:49:36+00:00\",\"dateModified\":\"2022-05-25T06:49:37+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/the-xorddos-botnet-is-back-targeting-linux-again\\\/\"},\"wordCount\":263,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/the-xorddos-botnet-is-back-targeting-linux-again\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/05\\\/Botnet.png\",\"keywords\":[\"Botnet\",\"Cybersecurity\"],\"articleSection\":[\"Botnets\",\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/the-xorddos-botnet-is-back-targeting-linux-again\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/the-xorddos-botnet-is-back-targeting-linux-again\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/the-xorddos-botnet-is-back-targeting-linux-again\\\/\",\"name\":\"The XorDdos Botnet is back targeting Linux again - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/the-xorddos-botnet-is-back-targeting-linux-again\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/the-xorddos-botnet-is-back-targeting-linux-again\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/05\\\/Botnet.png\",\"datePublished\":\"2022-05-25T06:49:36+00:00\",\"dateModified\":\"2022-05-25T06:49:37+00:00\",\"description\":\"The XorDdos Botnet has been active since at least 2014 and today we will talk about it because it has returned and is targeting Linux systems\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/the-xorddos-botnet-is-back-targeting-linux-again\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/the-xorddos-botnet-is-back-targeting-linux-again\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/the-xorddos-botnet-is-back-targeting-linux-again\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/05\\\/Botnet.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/05\\\/Botnet.png\",\"width\":1200,\"height\":630},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/the-xorddos-botnet-is-back-targeting-linux-again\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The XorDdos Botnet is back targeting Linux again\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The XorDdos Botnet is back targeting Linux again - Truxgo Server Blog","description":"The XorDdos Botnet has been active since at least 2014 and today we will talk about it because it has returned and is targeting Linux systems","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/the-xorddos-botnet-is-back-targeting-linux-again\/","og_locale":"es_MX","og_type":"article","og_title":"The XorDdos Botnet is back targeting Linux again - Truxgo Server Blog","og_description":"The XorDdos Botnet has been active since at least 2014 and today we will talk about it because it has returned and is targeting Linux systems","og_url":"https:\/\/truxgoservers.com\/blog\/the-xorddos-botnet-is-back-targeting-linux-again\/","og_site_name":"Truxgo Server Blog","article_published_time":"2022-05-25T06:49:36+00:00","article_modified_time":"2022-05-25T06:49:37+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/05\/Botnet.png","type":"image\/png"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/the-xorddos-botnet-is-back-targeting-linux-again\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/the-xorddos-botnet-is-back-targeting-linux-again\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"The XorDdos Botnet is back targeting Linux again","datePublished":"2022-05-25T06:49:36+00:00","dateModified":"2022-05-25T06:49:37+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/the-xorddos-botnet-is-back-targeting-linux-again\/"},"wordCount":263,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/the-xorddos-botnet-is-back-targeting-linux-again\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/05\/Botnet.png","keywords":["Botnet","Cybersecurity"],"articleSection":["Botnets","Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/the-xorddos-botnet-is-back-targeting-linux-again\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/the-xorddos-botnet-is-back-targeting-linux-again\/","url":"https:\/\/truxgoservers.com\/blog\/the-xorddos-botnet-is-back-targeting-linux-again\/","name":"The XorDdos Botnet is back targeting Linux again - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/the-xorddos-botnet-is-back-targeting-linux-again\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/the-xorddos-botnet-is-back-targeting-linux-again\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/05\/Botnet.png","datePublished":"2022-05-25T06:49:36+00:00","dateModified":"2022-05-25T06:49:37+00:00","description":"The XorDdos Botnet has been active since at least 2014 and today we will talk about it because it has returned and is targeting Linux systems","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/the-xorddos-botnet-is-back-targeting-linux-again\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/the-xorddos-botnet-is-back-targeting-linux-again\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/the-xorddos-botnet-is-back-targeting-linux-again\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/05\/Botnet.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/05\/Botnet.png","width":1200,"height":630},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/the-xorddos-botnet-is-back-targeting-linux-again\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"The XorDdos Botnet is back targeting Linux again"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4190","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=4190"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4190\/revisions"}],"predecessor-version":[{"id":4196,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4190\/revisions\/4196"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/4191"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=4190"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=4190"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=4190"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}