Linux Rabbit

MITRE ATT&CK: S0362 View on attack.mitre.org

Aliases: Linux Rabbit

First seen
2018-08-01 00:00:00
Malware type
cryptominer
Family
Malware family
Operating systems
linux
Profile updated
2026-07-07 15:28:15

Targeted industries: technology-and-telecommunications

Context

Linux Rabbit is malware that targeted Linux servers and IoT devices in a campaign lasting from August to October 2018. It shares code with another strain of malware known as Rabbot. The goal of the campaign was to install cryptocurrency miners onto the targeted servers and devices.

Detection coverage

  • 104 Sigma rules

Malware & tools used

  • Password Spraying (attack-pattern)
  • External Remote Services (attack-pattern)
  • Unix Shell Configuration Modification (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Data Encoding (attack-pattern)
  • Valid Accounts (attack-pattern)

Reports & references

  • MITRE ATT&CK — S0362 (report)
  • anomali.com — Pulling Linux Rabbit Rabbot Malware Out Of A Hat (report)

External references