New Sysrv Botnet Abuses Google Subdomain To Spread XMRig Miner
ID: 3e74d534-cbd5-5206-a00e-8119dd628f3c
STIX ID: report--3e74d534-cbd5-5206-a00e-8119dd628f3c
Feed Name: cybersecurityNews.com
Imperva researchers analyzed a Sysrv botnet variant (first seen 2020) that uses a Golang worm/dropper to exploit Apache Struts and Atlassian Confluence vulnerabilities, terminate security processes, spread via SSH and compromised domains, and deploy an XMRig Monero miner. The report details the infection chain, improved persistence and obfuscation techniques, second-stage binaries hosted on a Google subdomain, mining pool endpoints and wallet, and provides IoCs (URLs, file hashes) to aid detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
