z0Miner Is Spreading quickly by Exploiting ElasticSearch and Jenkins Vulnerabilities
released on 2021-03-10 @ 08:11:28 PM
z0Miner is a malicious mining family that became active last year and has been publicly analyzed by the Tencent Security Team. z0Miner initially exploited a Weblogic unauthorized remote command execution vulnerability for propagation.
Recently, the NetLab 360 Anglerfish honeypot system observed the z0Miner spreading by exploiting remote command execution vulnerabilities in ElasticSearch and Jenkins.