logo

Hackers Exploiting GeoServer RCE Vulnerability to Deploy CoinMiner

ID: 9a7bce39-e0a5-515d-9374-e623312ebee4

STIX ID: report--9a7bce39-e0a5-515d-9374-e623312ebee4

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-07-10

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A critical GeoServer RCE (CVE-2024-36401) is being actively exploited worldwide to deploy XMRig Monero miners and remote access tooling; attackers use PowerShell and Bash scripts to fetch malware, install NetCat reverse shells on Windows, register Cron-based persistence on Linux, and mine to pool.supportxmr.com:443, with documented compromises in South Korea.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.