Concrete signature match: Trojan - Appears legitimate but performs malicious actions for Linux platform, family Dakkatoni
This is a detection for a Linux trojan from the Dakkatoni malware family, identified through behavioral analysis. The malware infects Linux systems, often by brute-forcing SSH credentials, and enrolls the compromised device into a botnet. This botnet is then typically used to conduct Distributed Denial of Service (DDoS) attacks.
No detailed analysis available from definition files.
bdb2a340429242a515167156b091ee31de1398476c542695168caf17e640701c75371d8841c1495f6e3597aedba04a368a45d8c89b4e82fbc63602c70929a25aIsolate the affected Linux system from the network. Investigate the initial access vector, focusing on weak or compromised SSH credentials. Remove the malware and any persistence mechanisms (e.g., cron jobs). Change all credentials and harden SSH configurations to prevent reinfection.