WatchDog is a Linux-focused cryptojacking threat actor and malware operation active since at least 2019. It is associated with opportunistic compromise of exposed internet-facing services and deployment of persistent cryptocurrency-mining payloads on victim infrastructure. WatchDog is widely tracked as both a malware family and the operator behind campaigns that automate infection, persistence, and resource hijacking on Linux systems. The operation is known for aggressive post-compromise competition suppression typical of commodity cryptomining ecosystems. WatchDog-related activity has been observed using persistence mechanisms such as cron-based task injection and maintaining multiple process and service disguises to survive reboots and evade casual detection. The group’s tradecraft is consistent with financially motivated cryptomining campaigns that monetize unauthorized compute resources rather than espionage or destructive objectives. WatchDog has been referenced as one of several rival Linux miner families targeted for eviction by other cryptojacking malware, indicating its established presence in the broader Linux mining malware ecosystem. Observed WatchDog infections on compromised servers do not by themselves establish that the underlying infrastructure is operated by WatchDog, because exposed services are frequently victimized by third-party worms and miner botnets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a rival cryptomining family/operator whose known process names are included in the lambsys kill list.
Cryptojacking group associated with Redis compromise and crontab injection payloads; mentioned here as compromising a NEKOBYTE server as collateral activity, not as the operator of the MITM infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.