logo

Active Exploitation of New Apache Struts Vulnerability CVE-2018-11776 Deploys Cryptocurrency Miner

ID: fa457811-d718-5be4-b818-a15ed4c8533a

STIX ID: report--fa457811-d718-5be4-b818-a15ed4c8533a

Feed Name: Volexity Blog

Threat Score
70/100

Date Published: 2018-08-27

Date Updated: 2026-05-01

...
...

**Executive Summary:** Volexity observed active exploitation of Apache Struts CVE-2018-11776 beginning August 2018 where attackers leveraged a public PoC to achieve remote code execution and install CNRig cryptomining software; the report includes the exploit HTTP request, the upcheck.sh installer (which fetches multi-architecture ELF miners), malicious IPs, mining pool and account, and Suricata/Snort detection signatures, and recommends immediate patching to Struts 2.3.35 / 2.5.17 and limiting external exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.