Linuxsys is a long-running cryptocurrency-mining intrusion campaign active since at least late 2021 that exploits publicly known vulnerabilities in internet-facing applications to deploy a miner on compromised systems. Observed exploitation has included Apache HTTP Server CVE-2021-41773 as well as additional n-day vulnerabilities affecting OSGeo GeoServer, Atlassian Confluence, Chamilo LMS, Metabase, and Palo Alto Networks firewalls. The operators consistently abuse compromised legitimate websites and other third-party infrastructure to stage payloads, which increases stealth and complicates detection and attribution. Persistence has been established through automated startup scripting, and the campaign has shown tradecraft intended to evade simplistic monitoring, including behavior that is less likely to appear in low-interaction honeypots. Artifacts associated with the campaign have included scripts with Sundanese-language comments, suggesting a possible Indonesian nexus, but this is not sufficient for high-confidence attribution to a state or formal intrusion set. The campaign’s dominant objective is illicit cryptomining rather than espionage or disruptive activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.