WatchDog is a long-running cryptojacking operation focused on illicit Monero mining, active since at least early 2019. It is best known for targeting exposed and vulnerable cloud-hosted Windows and Linux systems and for maintaining its own delivery infrastructure rather than relying primarily on third-party file hosting. The operation has been associated with sustained monetization through XMRig-based mining and with broad internet scanning and exploitation at scale. WatchDog uses a modular toolset that has included shell or PowerShell initialization scripts and multiple UPX-packed Go binaries. Observed components have performed network scanning and exploitation, miner deployment, miner watchdog and process supervision, and persistence management. The scanning component has targeted exposed services and applications including Drupal, Elasticsearch, Hadoop, Redis, ThinkPHP, SQL Server, Spring Data Commons, and Oracle WebLogic, and has incorporated numerous remote-code-execution paths. Persistence has been established through CronJobs on Unix-like systems and Scheduled Tasks on Windows. The malware also kills competing miners, removes or disables cloud security tooling, and restarts or re-downloads mining components when they are absent. The operation has shown cross-platform capability and cloud-oriented tradecraft. Researchers have assessed that compromised systems were primarily cloud instances running Windows and Unix-like operating systems. Because WatchDog commonly gains elevated privileges on victims, intrusions can create broader cloud-account risk beyond resource theft alone. WatchDog has also been linked to campaigns that deliberately mimicked TeamTNT tradecraft. In those cases, the operators reused naming conventions and infrastructure patterns associated with TeamTNT while retaining WatchDog-linked wallets, pools, and hosting overlaps. This suggests an effort to expand operations while obscuring attribution. At the same time, reporting distinguished WatchDog from TeamTNT by noting the absence in those campaigns of TeamTNT’s more recent credential-theft and container-focused behaviors. Known aliases and component names associated with WatchDog include pdefenderd, updatecheckerd, meminitsrv, dbused, phpguard, sysguard, phpupdate, zzh, trace, networkmanager, and networkservice. Overall, WatchDog is best characterized as a financially motivated, cloud-focused cryptojacking actor with scanning, exploitation, persistence, defense-evasion, and miner-protection capabilities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
61 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a rival cryptomining family/operator whose known process names are included in the lambsys kill list.
Cryptojacking group associated with Redis compromise and crontab injection payloads; mentioned here as compromising a NEKOBYTE server as collateral activity, not as the operator of the MITM infrastructure.
Conducting cryptojacking operations and mimicking TeamTNT infrastructure naming conventions and TTPs to mask activity. The campaign uses Monero mining, known WatchDog C2 infrastructure, and scripts that replace older WatchDog infrastructure while borrowing TeamTNT-style artifacts.
Referenced as a related cryptojacking campaign because one Sysrv sample reused a Monero wallet previously observed in WatchDog activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.