Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
After gaining access, the attacker modified files related to SSH services and added a trojan startup file to the system startup scripts. The trojan was discovered due to an error showing in a system log from a program not actually installed on the server (Xnest).
The link for this article located at ReadWriteWeb is no longer available.