Sysrv is a Golang-based multi-platform botnet and self-propagating worm first observed in 2020 that primarily targets internet-exposed Linux servers, with Windows variants also documented. Its operators use it to compromise vulnerable or weakly protected systems, establish persistence, spread laterally, and deploy XMRig for Monero cryptomining. Sysrv has been associated with broad opportunistic exploitation of public-facing services and applications, including numerous remote code execution flaws in enterprise and web software, as well as brute-force attacks against services such as SSH, MySQL, Tomcat, Jenkins, and WordPress. Public reporting has also linked Sysrv activity to exploitation of CVE-2017-9841 and other widely abused server-side vulnerabilities.
The malware commonly uses platform-specific loader scripts, including Bash on Linux and PowerShell on Windows, to retrieve and execute the main worm component and mining payloads. On Linux, later loaders added crontab-based persistence, SSH-based propagation, architecture preparation for mining, and extensive process-killing logic to remove competing miners, prior infections, and some defensive tooling. Sysrv samples have also been observed modifying host settings, cleaning shell history, attempting to disable firewalling or packet-filtering controls, and uninstalling or interfering with security software. The worm typically enforces single-instance execution through localhost TCP port checks that act as a mutex.
Sysrv’s propagation logic has evolved over time. Documented capabilities include random-IP scanning, SYN-based service discovery, exploitation of vulnerable applications, credential spraying and brute-force attacks, deployment of webshell or application-level payloads after successful compromise, and recursive SSH discovery using harvested host and key information. Some variants contain embedded exploit modules and hardcoded credential dictionaries, while others use staged download chains and trusted web services or compromised legitimate sites to host second-stage payloads. Later samples also introduced UPX packing and increasing levels of Golang obfuscation to hinder analysis.
The botnet’s primary monetization model is cryptojacking. Sysrv either drops or embeds XMRig and configures it to mine Monero through public pools or attacker-controlled proxy infrastructure. Early variants separated the worm and miner into distinct components, while later versions increasingly combined functionality. Sysrv has also been observed killing competing cryptominers and rival botnets to maximize resource control on infected hosts.
Sysrv is best characterized as a cryptomining botnet worm focused on Linux server environments but capable of operating across Linux and Windows. It has remained active for years, continuously incorporating new exploits, delivery chains, persistence mechanisms, and evasion features.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The requests shared common signatures and attempted to exploit multiple known web vulnerabilities in Apache Struts ( CVE-2017-9805 ) and Atlassian Confluence ( CVE-2023-22527 and CVE-2021-26084 ). | Sysrv is a well-documented botnet first identified in 2020, with the main payload being a worm written in Golang. It drops a cryptominer onto infected hosts before attempting to propagate itself using various methods, including network vulnerabilities.
The requests shared common signatures and attempted to exploit multiple known web vulnerabilities in Apache Struts ( CVE-2017-9805 ) and Atlassian Confluence ( CVE-2023-22527 and CVE-2021-26084 ). | Sysrv is a well-documented botnet first identified in 2020, with the main payload being a worm written in Golang. It drops a cryptominer onto infected hosts before attempting to propagate itself using various methods, including network vulnerabilities.
The requests shared common signatures and attempted to exploit multiple known web vulnerabilities in Apache Struts ( CVE-2017-9805 ) and Atlassian Confluence ( CVE-2023-22527 and CVE-2021-26084 ). | Sysrv is a well-documented botnet first identified in 2020, with the main payload being a worm written in Golang. It drops a cryptominer onto infected hosts before attempting to propagate itself using various methods, including network vulnerabilities.
The Ignition Remote Code Execution (RCE) exploit has the newest CVE number; it was published in January 2021 and was already used by Sysrv at the beginning of March. | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2017-9841 – PHPUnit RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2020-16846 – Saltstack RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2019-3396 – Atlassian Confluence RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2019-7238 – Nexus Repository Manager RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2018-7600 – Drupal RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2015-8562 – Joomla! RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2020-14882 – Oracle WebLogic RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2020-9496 – Apache OFBiz RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2019-0193 – Apache Solr RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2017-3066 – Adobe ColdFusion RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2018-1000861 – Jenkins RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2019-15107 – Webmin RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2019-10758 – Mongo Express RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2020-13942 – Apache Unomi RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2019-9193 – PostgreSQL RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2019-11581 – Atlassian Jira RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2017-11610 – Supervisor XML-RPC server RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2017-12149 – Jboss RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2017-5638 – Apache Struts RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Post exploitation, the malware will deliver a loader script: ld.sh for Linux and ld.ps1 for Windows. The loader is responsible for dropping and running the XMRig Miner and the Golang worm on the exploited service.
Two Sysrv loader scripts are circling for Linux and Windows: ldr.sh and ldr.ps1 ... the latter in Powershell
tries to infiltrate the servers with a hardcoded password dictionary attack
177 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet observed using CVE-2017-9841 in persistent exploitation campaigns.
A cross-platform Golang worm targeting Windows and Linux servers. It spreads by brute-forcing weak credentials on public-facing MySQL, Tomcat, and Jenkins services, and older variants also exploited WebLogic. After compromise it deploys loader scripts and installs XMRig miner at scale.
A botnet observed exploiting IoT devices, routers, and Apache HTTP servers to gain control of systems for malicious activity.
Linux-focused botnet malware associated with crypto mining, persistence via cron jobs, self-propagation, brute-forcing, and exploitation of vulnerable internet-facing applications such as WordPress to spread to additional hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.