Skip to content

BuildNot yet confirmed elsewhere1 publisher3 min readPublished

Outlaw botnet's 2022 SSH client outnumbers its newest fingerprint 618 sessions to 3 on one honeypot

Outlaw/Dota's 2022-era SSH client produced 618 sessions on one Cowrie honeypot in late September 2026, while a new client generation produced 3. A detection rule holding only the hassh published in May would have matched none of the 618.

The Engineer · Build desk

How we use AISend a correction

Illustration accompanying Outlaw botnet's 2022 SSH client outnumbers its newest fingerprint 618 sessions to 3 on one honeypot
Generated illustration

What happened

  • Of the 2022-client sessions, 407 ran no commands, 203 injected an SSH key and stopped, and 8 ran the full persistence chain.
  • Waves of logins started every 2 to 2.5 hours around the clock, 42 in all, with no daily pause.
  • One SANS ISC sensor logged the previous libssh_0.11.1 generation from 24 IPs and 3,473 SSH records between April 14 and 21, 2026.
  • Logins most often used the password 345gs5662d34 or 3245gs5662d34, the second paired with the root, test and user accounts.

Why it matters

  • constraint A host-side check for the mdrfckr key catches only about a third of these sessions; the other two thirds leave nothing to detect except a successful SSH login.
  • decision Teams pruning old hassh values from their rules now have a reason to keep them, since the 2022 hash was still the dominant one on this sensor in September 2026.
  • exposure A host that still accepts one of the logged passwords gets retried on a fixed cycle of a few hours, day and night.
  • precedent After three client swaps since late 2022, anyone maintaining a hassh list for this botnet should plan on adding another value.

The client fingerprint is the part of this botnet that keeps moving. The dev.to post lays out its history, oldest first:

1. October-November 2022: libssh-0.6.3 with hassh 51cba57125523ce4b9db67714a90bf6e, when port22 recorded 12,913 unique IPs from 152 countries [8]. 2. December 7, 2022: libssh_0.9.5 and 0.9.6 with hassh f555226df1963d1d3c09daf865abdc9a, across roughly 30,000 IPs [9]. 3. April 2026: libssh_0.11.1 with hassh 03a80b21afa810682a776a7d42e5e6fb, described on May 15 by Gokul Prema Thangavel in a SANS Internet Storm Center guest post [4]. 4. September 2026: a modified client cryptographic proposal, according to the dev.to author [3].

Other parts held still. The SSH key stayed the same through the December 2022 switch [9]. The April generation used the same compromise and persistence steps as its predecessor: reconnaissance, key injection, a password change and cleanup of competing bots [5]. The operators swap libssh builds and keep signing their key with the campaign's own name, the mdrfckr comment string [7]. The group, also tracked as Dota, has been documented since at least 2018 and spreads by brute-forcing SSH passwords [7].

The September generation is thin evidence so far: three sessions from one address [6]. On the author's Cowrie honeypot, the December 2022 client accounted for 618 sessions from 163 unique addresses, every one carrying hassh f555226df1963d1d3c09daf865abdc9a [1][2][17]. That works out to about 206 old-client sessions for each new one [19]. Only the SSH-2.0-libssh_0.9.6 banner appeared, though other researchers had also recorded 0.9.5 [12].

The session breakdown is the most useful part of the write-up for anyone maintaining rules. In the largest category the bot connected, made one login attempt and tore the session down in 1.6 seconds, with no commands after authentication [15]. Only 211 sessions, about 34%, put a key on the host [18]. A host-side check for the mdrfckr key sees that third. The rest exist only in SSH logs, as a successful login from a known client. Credential matching helps there, with one caveat from the author: Cowrie records logins selectively, so the credential list may be incomplete [11].

The author ties the regular spacing of the waves to central control. "This periodicity may indicate the use of a centralized scheduling mechanism rather than random activity from distributed nodes," the author wrote [22]. Wave sizes varied far more than the gaps between them, from 1 to 49 sessions with a median of 10 [14].

I would keep every published hassh in the rule set, the 2022 values included, and treat each one as a marker for a single generation [20][21]. For detection that survives the next client swap, I would weight the key and the post-login commands more heavily. Those held through the December 2022 switch and the April 2026 one [5][9].

What to watch

  • Whether other sensors, including SANS ISC's, log the new client proposal from more addresses than 36.134.69.15.
  • Whether the libssh_0.11.1 hassh 03a80b21afa810682a776a7d42e5e6fb keeps showing up after the September sightings or drops out.
  • Any change to the mdrfckr public key itself, which stayed fixed through the December 2022 client switch.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    In total, the author's honeypot recorded 618 sessions from 163 unique IP addresses in various countries.

    ReportedSupportedSource: dev.to honeypot write-up2 sources— create a free account to open themView cited source
  2. [2]

    Gen-2 sessions fell into three categories: 407 (65.86%) with no commands, 203 (32.85%) with key injection only, and 8 (1.29%) with the full persistence chain, all with hassh f555226df1963d1d3c09daf865abdc9a.

    ReportedSupportedSource: dev.to honeypot write-up2 sources— create a free account to open themView cited source
  3. [3]

    On September 27, the author's honeypot recorded a new generation of the Outlaw group's cryptomining botnet, featuring a modified client cryptographic proposal configuration and a significant regression.

    ReportedSupportedSource: dev.to honeypot write-upView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · October 1, 2026

    mdrfckr: The Outlaw/Dota Botnet Changes Its SSH Fingerprint Again

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories