Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

New Sysrv Botnet Variant Makes Use of Google Subdomain to Spread XMRig Miner

released on 2024-03-21 @ 11:09:46 AM
A new variant of the Sysrv botnet was observed exploiting vulnerabilities in Apache Struts and Atlassian Confluence to spread an XMRig cryptominer payload. The malware made use of a compromised Malaysian academic website and Google subdomain to distribute malicious files. Enhancements include obfuscation and architecture preparation functions. The malware connects to MoneroOcean mining pool endpoints and mines to a specific wallet. Defenders should block suspicious outbound connections and inspect seemingly legitimate sites for malicious files.