logo

New Sysrv Botnet Abuses Google Subdomain To Spread XMRig Miner

ID: 3e74d534-cbd5-5206-a00e-8119dd628f3c

STIX ID: report--3e74d534-cbd5-5206-a00e-8119dd628f3c

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2024-03-22

Date Updated: 2026-04-21

Author: Balaji N

...
...

Imperva researchers analyzed a Sysrv botnet variant (first seen 2020) that uses a Golang worm/dropper to exploit Apache Struts and Atlassian Confluence vulnerabilities, terminate security processes, spread via SSH and compromised domains, and deploy an XMRig Monero miner. The report details the infection chain, improved persistence and obfuscation techniques, second-stage binaries hosted on a Google subdomain, mining pool endpoints and wallet, and provides IoCs (URLs, file hashes) to aid detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.