Researchers reported that the Linux-based PGMiner botnet is compromising PostgreSQL servers to deploy Monero miners by abusing the disputed PostgreSQL remote code execution issue CVE-2019-9193 through the COPY FROM PROGRAM feature. The malware brute-forces PostgreSQL credentials, runs fileless payloads from database tables, downloads architecture-specific mining binaries, and routes command-and-control traffic through SOCKS5 proxies to onion-based infrastructure. Investigators said the malware also fingerprints victims, checks for virtualized environments, and masquerades as tracepath while tracking process IDs under /tmp/.X11-unix/.
PGMiner appears to build on tactics seen in the earlier SystemdMiner cryptomining botnet, which spread across Linux environments through exposed services, automation tools, and reused SSH keys while establishing persistence and deploying modified XMRig miners. Like SystemdMiner, PGMiner aggressively kills competing miners and security tools, but adds fallback methods to obtain curl and other refinements intended to improve resilience and stealth. Defenders were advised to remove the pg_execute_server_program privilege from untrusted PostgreSQL users and hunt for fake tracepath processes and related artifacts on exposed database hosts.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
DDG came back online with new C2 servers at 109.237.25.145 and 104.128.230.16 and upgraded to version v4000 with configuration version 25. The update added hosts-file blocks for multiple SystemdMiner C2 domains, indicating conflict between the botnets.
Researchers observed the DDG botnet update its configuration and malicious i.sh script from C2 server 119.9.106.27, adding a section that downloaded a separate malware set. The new programs killed DDG processes and removed DDG cron artifacts from infected hosts.
The PostgreSQL Global Development Group published a notice stating that CVE-2019-9193 is not a legitimate security vulnerability and that the CVE entry was filed in error. It clarified that COPY FROM PROGRAM is intentionally limited to superusers or the pg_execute_server_program role and does not cross an existing security boundary.
Unit 42 described PGMiner as a Linux-based Monero-mining botnet that brute-forces PostgreSQL credentials and abuses the disputed CVE-2019-9193 via "COPY FROM PROGRAM" for fileless payload execution. The report also detailed its Tor-backed C2 infrastructure, victim fingerprinting, architecture-specific payloads, and efforts to kill competing miners and security tools.
Netlab 360 published analysis of the newly named SystemdMiner botnet, describing its independent infrastructure, propagation via YARN and admin tools, SSH-based lateral movement, persistence, and XMRig-based mining payload.
The PostgreSQL feature "COPY FROM PROGRAM," later abused by PGMiner for code execution on database servers, was introduced in PostgreSQL 9.3.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 59 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
db-engines.com
Open sourceunit42.paloaltonetworks.com
Open sourceblog.netlab.360.com
Open sourcepostgresql.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.