BuildNot yet confirmed elsewhere1 publisher3 min readPublished
Outlaw botnet's 2022 SSH client outnumbers its newest fingerprint 618 sessions to 3 on one honeypot
Outlaw/Dota's 2022-era SSH client produced 618 sessions on one Cowrie honeypot in late September 2026, while a new client generation produced 3. A detection rule holding only the hassh published in May would have matched none of the 618.
The Engineer · Build desk

What happened
- Of the 2022-client sessions, 407 ran no commands, 203 injected an SSH key and stopped, and 8 ran the full persistence chain.
- Waves of logins started every 2 to 2.5 hours around the clock, 42 in all, with no daily pause.
- One SANS ISC sensor logged the previous libssh_0.11.1 generation from 24 IPs and 3,473 SSH records between April 14 and 21, 2026.
- Logins most often used the password 345gs5662d34 or 3245gs5662d34, the second paired with the root, test and user accounts.
Why it matters
- constraint A host-side check for the mdrfckr key catches only about a third of these sessions; the other two thirds leave nothing to detect except a successful SSH login.
- decision Teams pruning old hassh values from their rules now have a reason to keep them, since the 2022 hash was still the dominant one on this sensor in September 2026.
- exposure A host that still accepts one of the logged passwords gets retried on a fixed cycle of a few hours, day and night.
- precedent After three client swaps since late 2022, anyone maintaining a hassh list for this botnet should plan on adding another value.
The client fingerprint is the part of this botnet that keeps moving. The dev.to post lays out its history, oldest first:
1. October-November 2022: libssh-0.6.3 with hassh 51cba57125523ce4b9db67714a90bf6e, when port22 recorded 12,913 unique IPs from 152 countries [8]. 2. December 7, 2022: libssh_0.9.5 and 0.9.6 with hassh f555226df1963d1d3c09daf865abdc9a, across roughly 30,000 IPs [9]. 3. April 2026: libssh_0.11.1 with hassh 03a80b21afa810682a776a7d42e5e6fb, described on May 15 by Gokul Prema Thangavel in a SANS Internet Storm Center guest post [4]. 4. September 2026: a modified client cryptographic proposal, according to the dev.to author [3].
Other parts held still. The SSH key stayed the same through the December 2022 switch [9]. The April generation used the same compromise and persistence steps as its predecessor: reconnaissance, key injection, a password change and cleanup of competing bots [5]. The operators swap libssh builds and keep signing their key with the campaign's own name, the mdrfckr comment string [7]. The group, also tracked as Dota, has been documented since at least 2018 and spreads by brute-forcing SSH passwords [7].
The September generation is thin evidence so far: three sessions from one address [6]. On the author's Cowrie honeypot, the December 2022 client accounted for 618 sessions from 163 unique addresses, every one carrying hassh f555226df1963d1d3c09daf865abdc9a [1][2][17]. That works out to about 206 old-client sessions for each new one [19]. Only the SSH-2.0-libssh_0.9.6 banner appeared, though other researchers had also recorded 0.9.5 [12].
The session breakdown is the most useful part of the write-up for anyone maintaining rules. In the largest category the bot connected, made one login attempt and tore the session down in 1.6 seconds, with no commands after authentication [15]. Only 211 sessions, about 34%, put a key on the host [18]. A host-side check for the mdrfckr key sees that third. The rest exist only in SSH logs, as a successful login from a known client. Credential matching helps there, with one caveat from the author: Cowrie records logins selectively, so the credential list may be incomplete [11].
The author ties the regular spacing of the waves to central control. "This periodicity may indicate the use of a centralized scheduling mechanism rather than random activity from distributed nodes," the author wrote [22]. Wave sizes varied far more than the gaps between them, from 1 to 49 sessions with a median of 10 [14].
I would keep every published hassh in the rule set, the 2022 values included, and treat each one as a marker for a single generation [20][21]. For detection that survives the next client swap, I would weight the key and the post-login commands more heavily. Those held through the December 2022 switch and the April 2026 one [5][9].
What to watch
- Whether other sensors, including SANS ISC's, log the new client proposal from more addresses than 36.134.69.15.
- Whether the libssh_0.11.1 hassh 03a80b21afa810682a776a7d42e5e6fb keeps showing up after the September sightings or drops out.
- Any change to the mdrfckr public key itself, which stayed fixed through the December 2022 client switch.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
In total, the author's honeypot recorded 618 sessions from 163 unique IP addresses in various countries.
ReportedSupportedSource: dev.to honeypot write-up2 sources— create a free account to open themView cited source - [2]
Gen-2 sessions fell into three categories: 407 (65.86%) with no commands, 203 (32.85%) with key injection only, and 8 (1.29%) with the full persistence chain, all with hassh f555226df1963d1d3c09daf865abdc9a.
ReportedSupportedSource: dev.to honeypot write-up2 sources— create a free account to open themView cited source - [3]
On September 27, the author's honeypot recorded a new generation of the Outlaw group's cryptomining botnet, featuring a modified client cryptographic proposal configuration and a significant regression.
- [4]
On 2026-05-15, researcher Gokul Prema Thangavel published a guest post on the SANS Internet Storm Center describing the third generation of the mdrfckr botnet, with client banner SSH-2.0-libssh_0.11.1 and hassh 03a80b21afa810682a776a7d42e5e6fb.
- [5]
The third generation used compromise and persistence techniques identical to those of the previous one; TTPs remained nearly unchanged: reconnaissance, key injection, password change, and competitor cleanup.
- [6]
The author's Cowrie honeypot recorded the new generation over 2026-09-25 to 2026-09-30: three sessions with an average duration of approximately 4.6 seconds from IP address 36.134.69.15 (ASN AS56044).
- [7]
The campaign, known by the mdrfckr comment string in the public SSH key, belongs to the Outlaw botnet, also known as Dota, documented since at least 2018; it spreads via SSH brute-force and removes artifacts of competing botnets from compromised hosts.
- [8]
In October-November 2022, port22 recorded 12,913 unique IPs from 152 countries associated with mdrfckr, using client libssh-0.6.3 with hassh 51cba57125523ce4b9db67714a90bf6e; the bot performed reconnaissance, changed the root password and added an SSH key to authorized_keys.
- [9]
On December 7, 2022, the botnet switched to libssh_0.9.5/0.9.6 with hassh f555226df1963d1d3c09daf865abdc9a; approximately 30,000 IPs were recorded, with commands to remove protection from .ssh and reinfect the host. The SSH key remained unchanged.
- [10]
In April 2026, SANS ISC recorded the libssh_0.11.1 client with hassh 03a80b21afa810682a776a7d42e5e6fb; on a single sensor, 24 IPs and 3,473 SSH records were found over 8 days, April 14-21.
- [11]
The most frequently used credential combinations were 345gs5662d34/345gs5662d34, root/3245gs5662d34, test/3245gs5662d34 and user/3245gs5662d34; Cowrie selectively records logins and passwords, so the data does not necessarily reflect the complete set of credentials used.
- [12]
Researchers recorded two Gen-2 client banners, SSH-2.0-libssh_0.9.5 and SSH-2.0-libssh_0.9.6; in the author's own observation only SSH-2.0-libssh_0.9.6 was recorded.
- [13]
During the Gen-2 activity period, 42 waves were recorded; intervals between wave starts were mostly around 2-2.5 hours, waves were observed around the clock with no daily pauses.
- [14]
Waves lasted from a few minutes to about 2 hours, median 17 minutes, and covered 1 to 49 sessions from different IPs, median 10; the number of sessions per wave was irregular while intervals between waves stayed relatively stable.
- [15]
In the largest category the bot connects, makes a single login attempt and initiates teardown; the session lasts 1.6 seconds and no commands are executed after successful authentication.
- [16]
The first Gen-2 waves on the author's honeypot were observed on September 27, for example 07:35 with 9 sessions followed by 09:06 with 24 sessions.
- [17]
The three Gen-2 session categories sum to 618, the honeypot's full session count, so every one of the 618 sessions carried hassh f555226df1963d1d3c09daf865abdc9a.
- [18]
211 of the 618 Gen-2 sessions, about 34%, injected an SSH key (key-injection-only plus full persistence chain).
- [19]
The honeypot logged about 206 Gen-2 sessions for each session from the new client generation.
- [20]
The botnet's SSH client has changed at least three times since late 2022: libssh-0.6.3 to libssh_0.9.5/0.9.6 (Dec 2022), to libssh_0.11.1 (Apr 2026), to a modified cryptographic proposal (Sep 2026).
- [21]
A detection rule matching only the May 2026 hassh 03a80b21afa810682a776a7d42e5e6fb would have matched none of the 618 Gen-2 sessions on this honeypot.
- [22]
"This periodicity may indicate the use of a centralized scheduling mechanism rather than random activity from distributed nodes."
Sources
1 independent publisher whose own reporting we read for this story.
- dev.tomdrfckr: The Outlaw/Dota Botnet Changes Its SSH Fingerprint Again
1 article · October 1, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.