DIICOT Cryptojacking + P2P botnet (Monero) first seen 2021 6 chapters SSH cryptojacking documented since 2021. Two generations landed on the decoy back to back, and between one and the other the whole programme changed. DIICOT —also known as Mexals— is a veteran cryptojacking operation, documented since 2021 by Bitdefender and later by Akamai, Cado, Darktrace and Wiz. The name is the author’s own joke: it’s borrowed from a Romanian organised-crime agency. Its routine is textbook: brute-force in over SSH, evict the competition, install a Monero miner and hide it. Two generations landed on the decoy, and they’re worth keeping apart. The classic one —chapters 23 to 25— is the one documented for years. It hides the miner with a line in .bashrc that makes the top command lie, and it carries the wallet inside the binary, covered with toy encryption. Which is why with this one the money can be followed down to the last payout. The 2026 build —chapters 26 to 28— changed programme entirely. Command stopped being client-server and became a peer-to-peer mesh that elects a leader, with the orders arriving over a Telegram chat; the binaries are obfuscated and packed; and the wallet no longer travels inside: it gets downloaded at start-up, from a server that dies when the campaign dies. The same family, with every door closed. https://blog.efespain.com/en/diicot/ #malware #cryptojacking #Monero #honeypot