Posted Mar 26, 2009 18:01 UTC (Thu) by smoogen (subscriber, #97)
Parent article: Linux botnets
I do not believe that this is the first Linux botnet. I mean most of the brute force SSH and PHP ones would seem to fit into this description. While they might break into Solaris/MacOS/Windows boxes running SSH, most of the binaries they try to install seem to be Linux.
One of the most common ones I have seen are the ones that brute-force ssh. If it gets into a system (most of them Linux) it would login into some Command and Control IRC system. The IRC bot would then command to see if it should rootkit itself, ssh brute force other boxes or just send out SPAM.
Another one we have seen looks for printers with embedded Linux and does similar to the psyb0t..