Inside Linux.BtcMine.174: How Dr.Web’s New Malware Hijacks Linux Systems

Dr.Web’s recent report reveals Linux.BtcMine.174, a sophisticated 1000‑line shell‑script trojan that exploits Dirty COW or CVE‑2013‑2094 for root access, disables dozens of antivirus processes, mines cryptocurrency, and spreads via SSH‑collected hosts, with its components’ SHA‑1 hashes published on GitHub.

ITPUB
ITPUB
ITPUB
Inside Linux.BtcMine.174: How Dr.Web’s New Malware Hijacks Linux Systems

Russian antivirus vendor Dr.Web has disclosed a new Linux‑based trojan named Linux.BtcMine.174 . Unlike typical Linux viruses, this malware consists of a shell script exceeding 1,000 lines and serves as the initial executable on compromised systems.

After gaining a foothold, the script searches the filesystem for directories with write permissions, replicates itself, and downloads additional modules. It then escalates privileges by exploiting either CVE‑2016‑5195 (Dirty COW) or CVE‑2013‑2094, after which it installs itself as a local daemon with root rights.

The trojan actively terminates a range of Linux antivirus processes, including safedog, aegis, yunsuo, clamd, avast, avgd, cmdavd, cmdmgd, drweb-configd, drweb-spider-kmod, esets, and xmirrord.

Once the environment is prepared, the primary payload launches cryptocurrency mining operations. Additionally, the malware downloads and executes other malicious components, gathers information about all remote servers accessed via SSH, and attempts to propagate to those hosts.

Dr.Web has published the SHA‑1 hashes of the trojan’s components on GitHub for verification:

https://github.com/DoctorWebLtd/malware-iocs/tree/master/Linux.BtcMine.174

Further technical details and analysis are available in Dr.Web’s official report:

https://vms.drweb.com/virus/?i=17645163

Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

Linuxinformation securityprivilege escalationmalwareCryptocurrency Mining
ITPUB
Written by

ITPUB

Official ITPUB account sharing technical insights, community news, and exciting events.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.