Hackers Exploiting GeoServer RCE Vulnerability to Deploy CoinMiner
ID: 9a7bce39-e0a5-515d-9374-e623312ebee4
STIX ID: report--9a7bce39-e0a5-515d-9374-e623312ebee4
Feed Name: cybersecurityNews.com
Threat Score
A critical GeoServer RCE (CVE-2024-36401) is being actively exploited worldwide to deploy XMRig Monero miners and remote access tooling; attackers use PowerShell and Bash scripts to fetch malware, install NetCat reverse shells on Windows, register Cron-based persistence on Linux, and mine to pool.supportxmr.com:443, with documented compromises in South Korea.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
