GeoServer RCE Exploited in CoinMiner Campaigns (Campaign)
ID: 8c559681-1b02-5091-aa8e-d8f05301f06b
STIX ID: report--8c559681-1b02-5091-aa8e-d8f05301f06b
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2026-01-24
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Researchers observed active exploitation of GeoServer remote code execution (CVE-2024-36401) in multiple coinminer campaigns that download and install XMRig using PowerShell, Bash, and certutil-based droppers. Three campaign types were identified: simple script-based deployments, certutil + RAR SFX droppers installing a disguised XMRig as a Windows service via NSSM, and hybrid campaigns that add remote-access tooling and attempts to disable Windows Defender for persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
