Before it drops a single miner binary, the bot runs lscpu. Then it checks RAM. Then disk space. Only after it’s satisfied your box is worth the trouble does it bother deploying anything. That’s the behavior an SANS Internet Storm Center intern documented this week in a guest diary on SSH brute-force attacks, and it’s a small but telling data point in a bigger story: the economics of cybercrime have gotten disturbingly rational. Attackers aren’t spraying payloads and hoping. They’re doing cost-benefit analysis on your infrastructure before they decide you’re worth compromising.
That shift matters more than any single exploit. Cybersecurity teams have spent two decades building defenses around the assumption that attackers act fast and sloppy. Automated, profit-driven crime doesn’t work that way anymore. It profiles targets, modularizes its tooling, and increasingly, it’s run like an actual business, complete with org charts, revenue targets, and quality control. Three stories this week trace that arc from a single SSH session all the way up to a regional criminal economy worth tens of billions of dollars a year.

Recon First: What the Honeypot Actually Captured
The ISC diary walks through a live capture: an attacker brute-forces SSH credentials, lands a shell, and instead of immediately dropping a payload, runs a sequence of enumeration commands. CPU core count, architecture, memory totals, available disk. It reads like a sysadmin doing capacity planning, because functionally, that’s exactly what it is. The bot is deciding whether your server has enough horsepower to be worth the electricity and detection risk of running a miner on it.
This is a meaningful evolution from the smash-and-grab cryptojacking campaigns of a few years ago, where attackers deployed miners indiscriminately and let the math work itself out across thousands of victims. A hardware-aware bot is more selective, which means it’s also more efficient at avoiding low-value targets that generate noise without payoff. For defenders, the implication is uncomfortable: brute-force protection isn’t just about stopping account takeover anymore. It’s about denying the reconnaissance step that makes the rest of the attack economically viable in the first place.
Modular Malware: Astaroth’s New Spambot Piece
CrowdStrike’s writeup on Astaroth’s new spambot component fits the same pattern from a different angle. Astaroth has been a persistent banking trojan family for years, and its operators keep treating it less like a monolithic piece of malware and more like a software product with a release cycle. The new spambot module is a discrete, swappable piece of functionality bolted onto an existing delivery chain, built to expand the malware’s self-propagation without requiring a rewrite of the core.
That modularity is the throughline connecting a single SSH recon script to an entire criminal economy. Modern malware families are built like microservices. Recon, delivery, persistence, and monetization are separate components that get mixed, matched, and resold independently. It’s why threat detection built around signature matching on a single “malware family” keeps losing ground. The component doing the damage in your environment today may be a rented piece of a completely different toolkit tomorrow, and your incident response playbook needs to account for that churn rather than treating each detection as a one-off.

The Business Case: SE Asia’s $88 Billion Year
Zoom all the way out and you get Dark Reading’s reporting on Southeast Asian cybercriminal syndicates, which have moved well past scam compounds into a diversified criminal-services economy that trafficked people from at least 80 countries and cost the region an estimated $88 billion in 2025 alone. These groups aren’t loose collectives anymore. They run recruitment pipelines, technical development teams, and money-laundering infrastructure at a scale that rivals mid-size multinational companies.
That’s the context the SSH recon bot and the Astaroth module actually belong to. Individual pieces of malware look small in isolation, but they’re outputs of organizations with budgets, headcount, and quarterly incentives to make their tooling more efficient. A bot that skips low-value targets isn’t being clever for its own sake. It’s optimizing for a business that has to justify its infrastructure spend like any other. Treating these as isolated technical curiosities misses the point: you’re not defending against a script kiddie anymore, you’re defending against a company’s product roadmap.
Hardening Checklist: Closing the Recon Window
None of this requires exotic defenses. Recon-driven, modular attacks are still beaten by the same fundamentals, applied more consistently. The goal is to make your environment expensive and unrewarding to profile in the first place.
- Move SSH off the default port and enforce key-based authentication only; brute-force bots targeting password auth on port 22 are the cheapest recon vector there is, and removing it kills a huge share of automated attempts before they start.
- Rate-limit and lock out repeated failed logins at the firewall level, not just the application layer, so reconnaissance attempts get throttled before a bot ever gets a working shell to enumerate from.
- Segment workloads so a compromised low-value host can’t be used as a pivot point to profile higher-value systems on the same network.
- Alert on enumeration commands themselves (
lscpu,free -m,df -hchained together in a short window from a new session) as an early indicator, not just on the payload that follows. - Treat malware detections as components, not families; when your threat detection stack flags a spambot or loader module, assume it’s rented or reused elsewhere and hunt for it across your environment rather than closing the ticket on one host.
Longer term, this is a defense-in-depth argument, not a single-control fix. Security hardening on the host, network segmentation, and identity controls all need to work together, because an attacker doing cost-benefit math will simply route around whichever single layer is weakest. Incident response teams should also start logging and reviewing recon-stage activity specifically, since the profiling step is often the only window where you can stop an attack before it becomes economically committed for the attacker.
Sources
- Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner [Guest Diary]
- Inside Astaroth’s New Spambot Component
- SE Asian Cybercriminal Syndicates Become a Global Power
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
