well fun morning, server from friends got epic haxored so i did forensics from my phone, in bed

- ssh with password auth enabled
- ssh'd into minecraft user with apparently weak password
- deployed payload, consisting of an irc c&c, and a monero miner disguised as 'kswapd0'

by far not the only ones, for example blog.alvarezp.org/2020/06/18/m

Follow

and slightly more in-depth writeup, yoroi.company/research/outlaw-
the 'c' component is actually what alerted us, with abuse email sent from another provider 'hey pls stop bruteforcing our hosts'

Sign in to participate in the conversation
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.