Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More
New: 2026 Gartner® Market Guide for Adversarial Exposure Validation
Learn More
New Research: Exploiting Configuration Trust in AI Coding Tools
Learn More
New Case Study: How a Financial Authority Validates Cyber Resilience
Learn More

Shc Linux Malware Used To Install XMRig CoinMiner And DDoS Botnet

January 11, 2023

External facing Linux servers in South Korea were targeted with a Shc (Shell Script Compiler) downloader, XMRig coin miner, and DDoS IRC botnet. XMRig was used to mine for digital currency while the botnet was used to perform TCP, UDP, and HTTP DDoS flood attacks. The botnet also contained additional commands including command execution, reverse shell, port scanning, and log deletion.