Sysrv is a Golang-based multi-platform cryptojacking botnet and self-propagating worm active since late 2020. It primarily targets exposed Linux and Windows servers and is operated to deploy XMRig for Monero mining at scale. Sysrv has been observed spreading through platform-specific loader scripts and malware binaries, with Linux activity especially prominent, while Windows delivery and persistence mechanisms have also been documented.
Sysrv combines scanning, brute-force, exploitation, and miner deployment in a single campaign. It has targeted internet-facing services including Tomcat, Jenkins, MySQL, WebLogic, WordPress, Redis, Apache Flink, Apache NiFi, Apache Hadoop YARN, Jupyter Notebook, ThinkPHP, XXL-JOB, and SSH, and it has incorporated a broad set of remote code execution vulnerabilities over time, including CVE-2017-9841, CVE-2020-14882, and numerous other server-side flaws. It also performs password-spraying and brute-force attacks against weakly protected services such as MySQL, Tomcat, Jenkins, WordPress, and SSH to gain execution on additional hosts.
On compromise, Sysrv typically retrieves a Bash loader on Linux or a PowerShell loader on Windows, then installs both the worm component and an XMRig miner. Earlier variants stored the propagation module and miner separately, while later variants combined functionality more tightly and in some cases embedded the miner directly in the Golang binary. Linux variants have used single-instance checks via localhost TCP ports as a mutex mechanism, established persistence through cron, and modified the environment to improve miner survivability. Observed loader behavior includes terminating competing miners and botnets, clearing shell history, removing temporary artifacts, altering DNS settings, attempting to disable host defenses, and in some cases adding persistence through scheduled execution or SSH-related changes. Windows delivery chains have also used in-memory PowerShell execution, disabled the firewall, killed competing miners, and established persistence through scheduled tasks and autorun mechanisms.
Sysrv has shown steady operational evolution. Linux samples have been grouped into multiple variants, with widespread use of UPX packing and later obfuscation through Golang-focused tooling. Some samples proxy mining traffic through attacker-controlled infrastructure rather than connecting directly to public pools. The malware has also been observed in exploitation chains involving web shells and server-side application vulnerabilities, including Spring4Shell attempts used to deliver Windows and Linux loader payloads.
The malware’s core purpose is cryptocurrency mining, but its broader behavior is characteristic of an opportunistic wormable botnet focused on rapid propagation, miner deployment, persistence, and defense evasion across heterogeneous server environments. Sysrv has been associated with mass exploitation of exposed enterprise and internet-facing services rather than sector-specific targeting, and it has remained relevant in botnet exploitation activity through at least 2026.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Exploits with the corresponding CVE number: CVE-2019-10758 – Mongo Express RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2020-14882 – Oracle WebLogic RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2018-1000861 – Jenkins RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2020-16846 – Saltstack RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2019-0193 – Apache Solr RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2020-9496 – Apache OFBiz RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
The Ignition Remote Code Execution (RCE) exploit has the newest CVE number; it was published in January 2021 and was already used by Sysrv at the beginning of March. | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2017-9841 – PHPUnit RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2019-15107 – Webmin RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2019-3396 – Atlassian Confluence RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2015-8562 – Joomla! RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2019-7238 – Nexus Repository Manager RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2018-7600 – Drupal RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2019-9193 – PostgreSQL RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2017-12149 – Jboss RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2017-11610 – Supervisor XML-RPC server RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2020-13942 – Apache Unomi RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2017-3066 – Adobe ColdFusion RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2017-5638 – Apache Struts RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
Exploits with the corresponding CVE number: CVE-2019-11581 – Atlassian Jira RCE | This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This blog post takes a deep dive into the Sysrv botnet, which first made headlines at the end of December 2020 and has continued to evolve since then.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Edit crontab file to achieve persistence... If crontab command is not available install cron via apt, crontabs via yum and start the appropriate services
Post exploitation, the malware will deliver a loader script: ld.sh for Linux and ld.ps1 for Windows. The loader is responsible for dropping and running the XMRig Miner and the Golang worm on the exploited service.
Two Sysrv loader scripts are circling for Linux and Windows: ldr.sh and ldr.ps1 , respectively.
Edit crontab file to achieve persistence... If crontab command is not available install cron via apt, crontabs via yum and start the appropriate services
The first obfuscated sample appeared in April 2021... This sample also had obfuscated Go packages and some function names... the obfuscation tool used is gobfuscate
Upon executing the binary in a controlled environment... the binary operates under the name kthreaddk, a frequently observed identifier for this strain of malware.
tries to infiltrate the servers with a hardcoded password dictionary attack... WordPress brute-force... SSH brute-force
164 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet observed using CVE-2017-9841 in persistent exploitation campaigns.
A cross-platform Golang worm targeting Windows and Linux servers. It spreads by brute-forcing weak credentials on public-facing MySQL, Tomcat, and Jenkins services, and older variants also exploited WebLogic. After compromise it deploys loader scripts and installs XMRig miner at scale.
Linux-focused botnet malware associated with crypto mining, persistence via cron jobs, self-propagation, brute-forcing, and exploitation of vulnerable internet-facing applications such as WordPress to spread to additional hosts.
A cryptocurrency miner family referenced as competing miner activity; the dropped PowerShell script kills sysrv-related processes before downloading and launching its own miner binary.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.