← Back to capsules
DevOps Seguridad CloudSecurity Linux SSH Backend

I audited a VPS and found a worm that had been inside for 6 days

Published on July 15, 2026

𝗜 𝗮𝘂𝗱𝗶𝘁𝗲𝗱 𝗮 𝗩𝗣𝗦 𝗮𝗻𝗱 𝗳𝗼𝘂𝗻𝗱 𝗮 𝘄𝗼𝗿𝗺 𝘁𝗵𝗮𝘁 𝗵𝗮𝗱 𝗯𝗲𝗲𝗻 𝗶𝗻𝘀𝗶𝗱𝗲 𝗳𝗼𝗿 𝟲 𝗱𝗮𝘆𝘀

145 CPU hours. An intruder operating in silence. And it got in without asking for a password. 😅

The task was simple: audit a VPS before taking it offline, check that nothing was pending, and shut it down cleanly to avoid unnecessary charges. Nothing out of the ordinary. But when I reviewed the logs, I found something I didn't expect: SSH access as root, authenticated with a public key that shouldn't have been there.

The worm belonged to the 𝗧𝗲𝗮𝗺𝗧𝗡𝗧 botnet, known for attacking cloud infrastructure. Its technique wasn't brute force — it was more elegant and more dangerous 🔥: it exploited services exposed without a 𝗳𝗶𝗿𝗲𝘄𝗮𝗹𝗹, injected its own 𝗦𝗦𝗛 𝗸𝗲𝘆 into `authorized_keys` overwriting the previous ones, and walked in cleanly as if it owned the place. Once inside it installed a 𝗠𝗼𝗻𝗲𝗿𝗼 𝗺𝗶𝗻𝗲𝗿 and secured persistence via 𝗰𝗿𝗼𝗻𝘁𝗮𝗯. No noise. No alerts.

The server had been "apparently unused" for days — but it kept working. For the attackers. 💻

What I took from this:

🔒 𝗙𝗶𝗿𝗲𝘄𝗮𝗹𝗹 𝗯𝗲𝗳𝗼𝗿𝗲 𝗲𝘅𝗽𝗼𝘀𝗶𝗻𝗴 𝗮𝗻𝘆 𝘀𝗲𝗿𝘃𝗶𝗰𝗲. No exceptions.

🔑 𝗖𝗼𝗻𝘁𝗿𝗼𝗹 𝘄𝗵𝗼 𝗰𝗮𝗻 𝗮𝘂𝘁𝗵𝗲𝗻𝘁𝗶𝗰𝗮𝘁𝗲: `authorized_keys` is not set-and-forget.

📋 𝗔𝘂𝗱𝗶𝘁 𝗯𝗲𝗳𝗼𝗿𝗲 𝘀𝗵𝘂𝘁𝘁𝗶𝗻𝗴 𝗱𝗼𝘄𝗻. What seems "unused" can be very active.

Do you have servers on pause that you never audit? 👇

Keep flying, Champions! ✈️