Linux Rabbit
MITRE ATT&CK: S0362 View on attack.mitre.org
Aliases: Linux Rabbit
- First seen
- 2018-08-01 00:00:00
- Malware type
- cryptominer
- Family
- Malware family
- Operating systems
- linux
- Profile updated
- 2026-07-07 15:28:15
Targeted industries: technology-and-telecommunications
Context
Linux Rabbit is malware that targeted Linux servers and IoT devices in a campaign lasting from August to October 2018. It shares code with another strain of malware known as Rabbot. The goal of the campaign was to install cryptocurrency miners onto the targeted servers and devices.
Detection coverage
- 104 Sigma rules
Malware & tools used
- Password Spraying (attack-pattern)
- External Remote Services (attack-pattern)
- Unix Shell Configuration Modification (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Data Encoding (attack-pattern)
- Valid Accounts (attack-pattern)
Reports & references
- MITRE ATT&CK — S0362 (report)
- anomali.com — Pulling Linux Rabbit Rabbot Malware Out Of A Hat (report)