logo

GeoServer RCE Exploited in CoinMiner Campaigns (Campaign)

ID: 8c559681-1b02-5091-aa8e-d8f05301f06b

STIX ID: report--8c559681-1b02-5091-aa8e-d8f05301f06b

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2026-01-24

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers observed active exploitation of GeoServer remote code execution (CVE-2024-36401) in multiple coinminer campaigns that download and install XMRig using PowerShell, Bash, and certutil-based droppers. Three campaign types were identified: simple script-based deployments, certutil + RAR SFX droppers installing a disguised XMRig as a Windows service via NSSM, and hybrid campaigns that add remote-access tooling and attempts to disable Windows Defender for persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.