Spreads via password authenticated SSH, which is the first thing you disable when you set up an SSH server. Doesn't hide its CPU usage. Does a few mildly crafty things to prevent reverse engineering, but overall this "worm" just seems like it's picking low-hanging fruit.
This doesn't seem serious at all, nor difficult to detect. Am I missing something?