External facing Linux servers in South Korea were targeted with a Shc (Shell Script Compiler) downloader, XMRig coin miner, and DDoS IRC botnet.
XMRig was used to mine for digital currency while the botnet was used to perform TCP, UDP, and HTTP DDoS flood attacks.
The botnet also contained additional commands including command execution, reverse shell, port scanning, and log deletion.