GeoServer, Where Various CoinMiner Attacks Occur
ID: 854d8d3f-1ca3-55ea-aa75-7dfba899a814
STIX ID: report--854d8d3f-1ca3-55ea-aa75-7dfba899a814
Feed Name: ASEC
Threat Score
**Executive Summary:** ASEC observed multiple threat actors actively exploiting the GeoServer remote code execution vulnerability (CVE-2024-36401) to install XMRig CoinMiner and other malware across Windows and Linux hosts; the report details three main attack patterns (PowerShell/bash execution, certutil RAR SFX droppers, and batch/NSSM-based downloaders), includes persistence and defense-evasion techniques, and provides IOCs (domains, IPs, and file hashes) for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
