SSHStalker Botnet Uses Legacy Exploits and IRC C2 to Hijack Linux Systems
VPN Central [Unofficial]
February 13, 2026
Cybersecurity researchers have uncovered a new Linux botnet operation known as SSHStalker, which targets exposed SSH servers and uses the classic Internet Relay Chat (IRC) protocol for command-and-control (C2). The botnet leverages a large catalog of old Linux kernel vulnerabilities to compromise systems, maintain persistent access, and enroll infected hosts into IRC control channels. According […]
The post SSHStalker Botnet Uses Legacy Exploits and IRC C2 to Hijack Linux Systems appeared first on VPN Central.
Discussion in the ATmosphere