Sysrv is a Go-based, self-propagating malware family and cryptomining botnet first publicly identified in December 2020. It targets Linux and Windows servers, compromising exposed services to deploy the XMRig miner for unauthorized Monero mining. Early variants separated the worm and miner components, while later variants combined them or retrieved additional mining payloads after infection.
Sysrv scans for vulnerable services and propagates through remote code execution vulnerabilities, hardcoded credential dictionaries, and SSH access using keys and host information discovered on compromised systems. Targets include MySQL, Apache Tomcat, Jenkins, Oracle WebLogic, and numerous web applications. Its exploit arsenal includes Apache Struts vulnerabilities, PHPUnit CVE-2017-9841, Spring Cloud Gateway CVE-2022-22947, and Atlassian Confluence vulnerabilities CVE-2021-26084 and CVE-2023-22527. Some variants use MySQL user-defined functions for command execution and privilege escalation. Platform-specific Bash and PowerShell loaders retrieve and execute the worm and mining components.
Linux variants establish persistence through cron jobs and authorized SSH keys, terminate competing miners, disable firewalls, and remove security software. They also clear shell history, masquerade as system processes, and use local TCP listeners as single-instance checks. Many binaries are packed with UPX, and later versions introduce Go code obfuscation. Campaigns have used compromised websites and legitimate hosting services to distribute encoded mining payloads. Sysrv's principal objective is monetizing compromised computing resources rather than stealing cryptocurrency wallets or credentials.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2017-5638, CVE-2022-22947 ... A Sysrv botnet instance written in Go.
CVE-2017-5638, CVE-2022-22947 ... A Sysrv botnet instance written in Go.
The requests shared common signatures and attempted to exploit multiple known web vulnerabilities in Apache Struts ( CVE-2017-9805 ) and Atlassian Confluence ( CVE-2023-22527 and CVE-2021-26084 ). | Sysrv is a well-documented botnet first identified in 2020, with the main payload being a worm written in Golang. It drops a cryptominer onto infected hosts before attempting to propagate itself using various methods, including network vulnerabilities.
The requests shared common signatures and attempted to exploit multiple known web vulnerabilities in Apache Struts ( CVE-2017-9805 ) and Atlassian Confluence ( CVE-2023-22527 and CVE-2021-26084 ). | Sysrv is a well-documented botnet first identified in 2020, with the main payload being a worm written in Golang. It drops a cryptominer onto infected hosts before attempting to propagate itself using various methods, including network vulnerabilities.
The requests shared common signatures and attempted to exploit multiple known web vulnerabilities in Apache Struts ( CVE-2017-9805 ) and Atlassian Confluence ( CVE-2023-22527 and CVE-2021-26084 ). | Sysrv is a well-documented botnet first identified in 2020, with the main payload being a worm written in Golang. It drops a cryptominer onto infected hosts before attempting to propagate itself using various methods, including network vulnerabilities.
The Ignition Remote Code Execution (RCE) exploit has the newest CVE number; it was published in January 2021 and was already used by Sysrv at the beginning of March. | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2017-9841 – PHPUnit RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2020-16846 – Saltstack RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2019-3396 – Atlassian Confluence RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2019-7238 – Nexus Repository Manager RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2018-7600 – Drupal RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2015-8562 – Joomla! RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2020-14882 – Oracle WebLogic RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2020-9496 – Apache OFBiz RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2019-0193 – Apache Solr RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2017-3066 – Adobe ColdFusion RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2018-1000861 – Jenkins RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2019-15107 – Webmin RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2019-10758 – Mongo Express RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2020-13942 – Apache Unomi RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2019-9193 – PostgreSQL RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2019-11581 – Atlassian Jira RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2017-11610 – Supervisor XML-RPC server RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2017-12149 – Jboss RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Post exploitation, the malware will deliver a loader script: ld.sh for Linux and ld.ps1 for Windows. The loader is responsible for dropping and running the XMRig Miner and the Golang worm on the exploited service.
Two Sysrv loader scripts are circling for Linux and Windows: ldr.sh and ldr.ps1 ... the latter in Powershell
tries to infiltrate the servers with a hardcoded password dictionary attack
178 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet observed using CVE-2017-9841 in persistent exploitation campaigns.
A cross-platform Golang worm targeting Windows and Linux servers. It spreads by brute-forcing weak credentials on public-facing MySQL, Tomcat, and Jenkins services, and older variants also exploited WebLogic. After compromise it deploys loader scripts and installs XMRig miner at scale.
A botnet observed exploiting IoT devices, routers, and Apache HTTP servers to gain control of systems for malicious activity.
Linux-focused botnet malware associated with crypto mining, persistence via cron jobs, self-propagation, brute-forcing, and exploitation of vulnerable internet-facing applications such as WordPress to spread to additional hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.