Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Drupal Ajax RCE (CVE-2018-7600) is listed among vulnerabilities exploited by Sysrv-hello in active attacks. | Sysrv-hello's propagator component aggressively scans the Internet for more vulnerable systems to add to its army of Monero mining bots with exploits targeting vulnerabilities that allow it to execute malicious code remotely.
Apache Solr (CVE-2019-0193) is listed among exploits used by Sysrv-hello in the past. | Sysrv-hello's propagator component aggressively scans the Internet for more vulnerable systems to add to its army of Monero mining bots with exploits targeting vulnerabilities that allow it to execute malicious code remotely.
PHPUnit (CVE-2017-9841) appears in the list of exploits used by the botnet in the past. | Sysrv-hello's propagator component aggressively scans the Internet for more vulnerable systems to add to its army of Monero mining bots with exploits targeting vulnerabilities that allow it to execute malicious code remotely.
Other exploits used by the botnet in the past also include Oracle Weblogic (CVE-2020-14882). | Sysrv-hello's propagator component aggressively scans the Internet for more vulnerable systems to add to its army of Monero mining bots with exploits targeting vulnerabilities that allow it to execute malicious code remotely.
Saltstack RCE (CVE-2020-16846) is listed among six vulnerabilities exploited by malware samples collected in active attacks. | Sysrv-hello's propagator component aggressively scans the Internet for more vulnerable systems to add to its army of Monero mining bots with exploits targeting vulnerabilities that allow it to execute malicious code remotely.
Sonatype Nexus Repository Manager (CVE-2019-7238) is listed among exploits used by the botnet in the past. | Sysrv-hello's propagator component aggressively scans the Internet for more vulnerable systems to add to its army of Monero mining bots with exploits targeting vulnerabilities that allow it to execute malicious code remotely.
Other exploits used by the botnet in the past also include Laravel (CVE-2021-3129). | Sysrv-hello's propagator component aggressively scans the Internet for more vulnerable systems to add to its army of Monero mining bots with exploits targeting vulnerabilities that allow it to execute malicious code remotely.
Atlassian Confluence Server (CVE-2019-3396) is listed among exploits used by the botnet in the past. | Sysrv-hello's propagator component aggressively scans the Internet for more vulnerable systems to add to its army of Monero mining bots with exploits targeting vulnerabilities that allow it to execute malicious code remotely.
Juniper identified Mongo Express RCE (CVE-2019-10758) among six vulnerabilities exploited by malware samples collected in active attacks. | Sysrv-hello's propagator component aggressively scans the Internet for more vulnerable systems to add to its army of Monero mining bots with exploits targeting vulnerabilities that allow it to execute malicious code remotely.
XML-RPC (CVE-2017-11610) appears among the vulnerabilities exploited by Sysrv-hello samples collected in active attacks. | Sysrv-hello's propagator component aggressively scans the Internet for more vulnerable systems to add to its army of Monero mining bots with exploits targeting vulnerabilities that allow it to execute malicious code remotely.
Jboss Application Server (CVE-2017-12149) is listed among exploits used by Sysrv-hello in the past. | Sysrv-hello's propagator component aggressively scans the Internet for more vulnerable systems to add to its army of Monero mining bots with exploits targeting vulnerabilities that allow it to execute malicious code remotely.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cross-platform mining botnet that infects Linux and Windows systems. In this update it adds Linux-side web file tampering via a.py, injecting an iframe into HTML/PHP/JSP/ASP/TPL pages to deliver BrowserUpdate.exe to visitors, while also turning compromised hosts into Monero miners.
Cryptomining botnet targeting Windows and Linux enterprise servers and cloud workloads. Active since December 2020, it exploits remote-code-execution vulnerabilities to deploy XMRig, kills competing miners, and spreads using SSH private keys collected from compromised servers. Initially using separate mining and propagation components, it evolved into a single binary supporting both functions. Mining configurations reference F2Pool and Nanopool, with MineXMR support removed from newer samples.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.