FritzFrog malware attacks SSH servers to mine Monero

silversurfer

Super Moderator
Thread author
Verified
Top Poster
Staff Member
Malware Hunter
Forum Veteran
Aug 17, 2014
12,726
123,827
8,399
A sophisticated botnet campaign named FritzFrog has been discovered breaching SSH servers around the world, since at least January 2020.

Written in Golang, FritzFrog is both a worm and a botnet that targets government, education, and finance sectors.
The attack has already managed to infiltrate over 500 servers in the U.S. and Europe, of universities and a railway company.

The advanced nature of FritzFrog lies in its proprietary and fileless P2P implementation written from scratch.
The malware assembles and executes the malicious payload entirely in-memory, making it volatile.
Full report by researchers: