WatchDog is a long-running cross-platform cryptojacking malware operation focused on mining Monero on compromised cloud and server infrastructure. Active since at least early 2019, it primarily targets Windows and Unix-like systems and has been observed infecting cloud instances at scale. The malware uses a modular toolkit composed of initialization scripts and multiple UPX-packed Go binaries that handle scanning and exploitation, miner protection and persistence, and XMRig-based cryptocurrency mining.
WatchDog’s infection chain commonly begins with a shell or PowerShell script that removes competing miners, disables or uninstalls cloud security tooling, downloads the remaining toolkit components, and prepares the host for mining. Its scanning and exploitation component performs broad network reconnaissance and attempts remote compromise of exposed services using numerous remote code execution paths. Documented targets include Drupal, Elasticsearch, Apache Hadoop, Redis, Spring Data Commons, ThinkPHP, SQL Server, and Oracle WebLogic Server. Persistence is established through CronJobs on Unix-like systems and Scheduled Tasks on Windows.
A dedicated watchdog-style component monitors the mining operation and helps keep the miner running, while another component protects the deployment by restarting missing payloads and maintaining persistence. WatchDog is also notable for aggressively evicting rival cryptominers and related malware from infected hosts. The operation has used attacker-controlled infrastructure for payload hosting rather than relying solely on third-party services, which contributed to its longevity.
WatchDog has also been linked to campaigns that deliberately mimicked TeamTNT tradecraft, including reuse of naming conventions and overlapping infrastructure patterns, while retaining WatchDog-associated wallets, pools, and operational characteristics. Those campaigns suggest an effort to expand cryptojacking activity while obscuring attribution. Because WatchDog often runs with elevated privileges on cloud systems, compromise can create broader risk beyond resource theft, including exposure of cloud-resident administrative data and credentials if present on the host.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Elasticsearch CVE-2015-1427 (Elasticsearch sandbox evasion – version before 1.3.8 and 1.4.x before 1.4.3) | Unit 42 researchers are exposing one of the largest and longest-lasting Monero cryptojacking operations known to exist. The operation is called WatchDog... The WatchDog miner is composed of a three-part Go Language binary set and a bash or PowerShell script file.
Oracle WebLogic Server CVE-2017-10271 – versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0 | Unit 42 researchers are exposing one of the largest and longest-lasting Monero cryptojacking operations known to exist. The operation is called WatchDog... The WatchDog miner is composed of a three-part Go Language binary set and a bash or PowerShell script file.
Spring Data Commons CVE-2018-1273, versions prior to 1.13-1.13.10, 2.0-2.0.5 | Unit 42 researchers are exposing one of the largest and longest-lasting Monero cryptojacking operations known to exist. The operation is called WatchDog... The WatchDog miner is composed of a three-part Go Language binary set and a bash or PowerShell script file.
CVE-2014-3120 (Elasticsearch before 1.2) | Unit 42 researchers are exposing one of the largest and longest-lasting Monero cryptojacking operations known to exist. The operation is called WatchDog... The WatchDog miner is composed of a three-part Go Language binary set and a bash or PowerShell script file.
Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed artificial intelligence (AI) application endpoints for obtaining initial access to enterprise networks.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
New WatchDog Malware There are two samples that show the evolution of WatchDog techniques to mimic TeamTNT operations... These samples... show the direct replacement of the known WatchDog C2 infrastructure with new C2 infrastructure.
New WatchDog Malware There are two samples that show the evolution of WatchDog techniques to mimic TeamTNT operations... These samples... show the direct replacement of the known WatchDog C2 infrastructure with new C2 infrastructure.
232 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
WatchDog is referenced as another competing cryptocurrency miner targeted for removal by the miner deployed through exploitation of Langflow.
Referenced as a competing cryptomining malware family whose processes are terminated by lambsys.
A rival cryptomining family identified through process names that lambsys attempts to terminate during competitive eviction on infected Linux hosts.
Cryptojacking malware/worm that compromises exposed Redis instances and installs cron-based payloads to mine cryptocurrency.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.