Watcher-NetAI / skn: a Linux SSH #botnet. 10 MB Go scanner with intact DWARF: source tree, module name, capability map, all visible. Loader is hardened; scanner is not
Full report [1/2]
https://t.co/F5X9zKwFEP
#SOC/#DFIR [2/2]
https://t.co/xOk92iRM6j
The threat model: compromise either side → operator pivots,
walker.ini glues the creds. Tiered IOCs in both reports.
📑 1/2 the Linux side
https://t.co/LYkw3o6W79
📑 2/2 the Windows arsenal and the back-pivot
https://t.co/eMrVi7aRXb
#ThreatIntel#DFIR
In Feb 2026 eSentire documented a #Prometei intrusion on Windows.
C2 = 103.176.111.176 (AS63737), Tor onion fallback.
In April our #honeypots caught the same campaign on Linux —
and the full Windows toolkit dropped alongside.
We just published a 2-part deep-dive 🧵👇
Cross-platform unity goes deeper than shared C2:
A 16-char constant Qwdrosd3grdsfFsz appears in BOTH the Windows
rdpcIip.exe AND the unpacked Linux zsvc.
walker.ini and the JSON schema are shared too.
Shared toolkit lineage, two operating systems.
@BleepinComputer Thanks @BleepinComputer
Full analysis below, shared few days before the CPanel wave: they also use ssh intrusion to spread. All data shared through 3 humble articles
New Linux ransomware-worm hybrid we're calling Sorry-worm.
It encrypts while it scans.
Caught it propagating in the wild from two unrelated SSH relays
within 8h of its first public sandbox submission.
3-part technical report ↓
https://t.co/hb67IVgUkX
New Linux ransomware-worm hybrid we're calling Sorry-worm.
It encrypts while it scans.
Caught it propagating in the wild from two unrelated SSH relays
within 8h of its first public sandbox submission.
3-part technical report ↓
https://t.co/hb67IVgUkX
The victim-ID file is a useful forensic detail:
sorry_id_<19-digit decimal>.sorry
(UNIX nanosecond timestamp. SOC teams finding such a file weeks after infection can date it to the nanosecond from the filename alone)
Decoder + analysis in Part 2:
https://t.co/2I8bHIC933
#vulnpocalypse ? The AI security debate has an asymmetry problem.
We talk as if AI upgrades attackers while defenders stay frozen in 2020. That is not what's happening.
What's missing is the other half → https://t.co/lz4zXKwfCZ
New cybersecurity research surface. Singapore. Tallinn.
Compromise, degradation, and uncertainty as baseline conditions.
#threatintel#honeypot#deception
https://t.co/R3sJUdddwj