logo

GeoServer, Where Various CoinMiner Attacks Occur

ID: 854d8d3f-1ca3-55ea-aa75-7dfba899a814

STIX ID: report--854d8d3f-1ca3-55ea-aa75-7dfba899a814

Feed Name: ASEC

Threat Score
70/100

Date Published: 2025-12-21

Date Updated: 2026-04-26

Author: ATCP

...
...

**Executive Summary:** ASEC observed multiple threat actors actively exploiting the GeoServer remote code execution vulnerability (CVE-2024-36401) to install XMRig CoinMiner and other malware across Windows and Linux hosts; the report details three main attack patterns (PowerShell/bash execution, certutil RAR SFX droppers, and batch/NSSM-based downloaders), includes persistence and defense-evasion techniques, and provides IOCs (domains, IPs, and file hashes) for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.