Empty SSH Logins Can Precede Miner Deployment

A quiet SSH login is not harmless noise here. The bot used the session to grade the host’s hardware first, so the early warning is the recon itself, before any miner shows up. A honeypot on an internet-facing SSH service saw a Go-based bot log in as root, check CPU, RAM, uptime, and GPU presence, then disconnect after a few seconds without dropping anything. The pattern fits cryptomining infrastructure that scores machines before deciding whether they are worth a payload. For defenders watching exposed SSH, the fingerprint and source from that empty session may be the only early link to later miner deployment.

Part of the PlainSec briefing for 2026-07-30

Sources