From:
BigBadBob-at-mrp3-dot-com@testing.local
https://cybersecurity.att.com/blogs/labs-research/teamtnt-with-new-campaign-aka-chimaera
There is apparently a Linux component that uses bash and python.
What the article does NOT say is HOW IT GOT THERE
However, I suspect that the CONSTANT POUNDING my ssh port gets (with corresponding Fail2Ban bans and logs) it probably spreads THAT way.
Apparently also affects K8s and (of course) Windows.
--
(aka 'Bombastic Bob' in case you wondered)
'Feeling with my fingers, and thinking with my brain' - me
'your story is so touching, but it sounds just like a lie'
"Straighten up and fly right"
--- SoupGate-Win32 v1.05
* Origin: www.darkrealms.ca (1:229/2)