FritzFrog malware attacks Linux servers over SSH to mine Monero
bleepingcomputer.com
bleepingcomputer.com
I can't help but wonder though; in a case like this where the malware is written in a relatively new language like Golang and uses some quite specialist techniques, whether the person behind it might be 'fingerprinting' themselves just by being one of a relatively small group of people who can do all of this 'stuff'?
Over 500 servers in the US and Europe belonging to government, education, healthcare and finance sectors have been breached already.
Guardicore Labs has identified the strand and provided remediation guidance.
Very strange pick of victims for a cryptominer. Can it be just a cover?