Linuxsys is a cryptocurrency miner, commonly described as a Linux cryptominer, used in a long-running campaign active since at least 2021. The campaign exploits known vulnerabilities in internet-facing applications to gain access and deploy the miner, including CVE-2021-41773 in Apache HTTP Server, CVE-2023-22527 in Atlassian Confluence, CVE-2023-34960 in Chamilo LMS, CVE-2023-38646 in Metabase, CVE-2024-36401 in OSGeo GeoServer GeoTools, and CVE-2024-0012 and CVE-2024-9474 affecting Palo Alto Networks firewalls. Delivery commonly occurs through a shell script named linux.sh, initially fetched from repositorylinux.org and then used to download miner binaries and configuration files from multiple compromised legitimate websites such as prepstarcenter.com, wisecode.it, dodoma.shop, portailimmersion.ca, and test.anepf.org. The campaign uses compromised legitimate infrastructure and valid SSL certificates for staging and evasion, and has been observed from attacking IP 103.193.177.152. Persistence is maintained with a script named cron.sh that ensures the miner restarts on reboot. The miner configuration points to the hashvault.pro Monero mining pool, and reporting cited roughly 400 infected hosts and modest Monero revenue. The operation has shown a consistent methodology over several years, relies on n-day exploitation, appears to avoid low-interaction honeypots, and may also involve Windows payloads including nssm.exe and winsys.exe found on compromised hosts. Public reporting notes Sundanese-language comments in related shell scripts, suggesting possible Indonesian origins, but attribution to a specific threat actor is not established in the provided content. Security vendors including VulnCheck, Darktrace, Fortinet, TrendMicro, and Imunify Security have tracked the campaign, and published indicators include SHA-1 hashes for linuxsys, config.sh, linux.sh, and cron.sh, along with related IPs, URLs, and detection rules.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...deploy a cryptocurrency miner called Linuxsys.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cryptominer malware referenced as being deployed via exploitation of an old Apache flaw.
Cryptocurrency miner deployed after exploiting Apache HTTP Server CVE-2021-41773 (per summary).
A Linux-focused cryptominer referenced by name.
Linuxsys is a cryptominer malware deployed on compromised Apache HTTP servers to mine cryptocurrency illicitly. Attackers exploit an old vulnerability to gain access and install the miner.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.