Outlaw/Dota botnet changes its SSH fingerprint again
A honeypot recorded a new generation of the mdrfckr botnet from the Outlaw (Dota) group between September 25 and 30, with a modified SSH client configuration. The botnet spreads via SSH brute-force, injects keys into authorized_keys and removes rival botnets' artifacts.
- Three sessions from IP 36.134.69.15 (AS56044) averaging about 4.6 seconds
- The mdrfckr campaign has been documented since 2018; in 2022 it spanned 12,913 IPs from 152 countries
- Gen-3 uses libssh_0.11.1 with hassh 03a80b21afa810682a776a7d42e5e6fb, first described in April 2026
- The bot changes the root password, injects its own SSH key and cleans up rival artifacts
Read next
Security