Sysrv Botnet is a cryptocurrency-mining botnet and worm first identified in 2020. It is primarily known for compromising Linux servers, with activity also documented against Windows systems, then deploying XMRig-based Monero mining payloads while continuing to propagate to additional hosts. The malware core is written in Golang, enabling cross-compilation across architectures and supporting a broad, evolving exploit set. Sysrv spreads through opportunistic internet-wide targeting of exposed services and vulnerable applications. Documented propagation methods include exploitation of numerous remote code execution flaws in enterprise and internet-facing software, scanning for vulnerable services, SSH-based propagation, and brute-force attacks against services such as SSH and WordPress. Reported exploit coverage has included products such as Apache Struts, Atlassian Confluence, GitLab, WebLogic, Tomcat, Redis, MySQL, Apache Hadoop YARN, Apache NiFi, Apache Flink, Jupyter Notebook, ThinkPHP, and XXL-JOB. The actor has repeatedly incorporated newly useful vulnerabilities to improve reach. Operationally, Sysrv commonly uses loader scripts to fetch and execute second-stage binaries. On Linux, these loaders have been observed adding persistence through cron, searching for SSH hosts and keys, installing hardcoded access material, killing competing miners and some security tooling, clearing traces, modifying resolver settings, and preparing the host for mining across different CPU architectures. Later variants also showed stronger obfuscation in Golang binaries, UPX packing, single-instance checks via TCP port binding, and listener functionality likely intended to support persistence or coordination. The botnet’s primary objective is illicit Monero mining rather than espionage or destructive effects. Over time, Sysrv evolved from separating worm and miner components into more integrated payloads, and some campaigns used trusted or compromised web infrastructure to stage malware and evade detection. One documented intrusion chain linked Sysrv activity to exploitation of CVE-2021-22205 on GitLab, resulting in miner deployment on a compromised server. Another campaign used exploit attempts against Apache Struts and Atlassian Confluence and staged payloads through compromised academic infrastructure. Known names include Sysrv and Sysrv Botnet. References to the operator ecosystem have also noted overlap or association with infrastructure previously seen in WatchDog cryptojacking activity, and some newer samples contained references to the #keksec operator milieu. Sysrv is best characterized as a financially motivated cryptojacking botnet focused on scalable initial access, worm-like propagation, persistence, defense evasion, and monetization through unauthorized cryptocurrency mining.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet campaign using a Golang worm to deploy XMRig cryptominers, propagate via SSH and exploitation of known web vulnerabilities, kill competing malware and security tools, and abuse compromised legitimate sites plus Google Sites for staging payloads.
Cryptomining botnet/worm campaign using GitLab CVE-2021-22205 to compromise exposed instances, drop a miner payload, and connect to mining infrastructure.
A Linux- and Windows-targeting worm/botnet focused on exploiting vulnerable internet-facing services, brute-forcing credentials, spreading to servers, establishing persistence, and deploying XMRig to mine Monero.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.