A new version of a Linux crypto-mining malware has evolved with new features while retaining its previous functionality. The new malware version only targets cloud environments and is now seeking out and removing any other cryptojacking scripts that may have previously infected the system. The malware adds their user accounts to the sudoers list, giving them root access to the device. The attackers use their own ssh-RSA key to perform system modifications and change the file permissions to a locked state. The actors install the Tor proxy service to protect communications from network scanning detection and scrutiny.”]