Researchers reported that the WatchBog cryptomining botnet expanded its tooling beyond Linux-focused exploitation by adding a BlueKeep scanning module that probes RDP services on TCP 3389 for potentially vulnerable Windows hosts. The malware, active since at least 2018, primarily targets unpatched Linux systems and spreads through a Cython-compiled ELF implant that pulls command-and-control data from Pastebin, falls back to a hardcoded .onion service, and communicates over HTTPS without proper certificate validation. That TLS weakness allowed defenders to intercept tasking and victim telemetry, helping estimate roughly 4,500 infections tied to observed infrastructure, though the total may be higher.
Across observed campaigns, WatchBog and related Linux miner activity exploited widely known flaws in Jira, Exim, Solr, Jenkins, Nexus Repository Manager 3, Confluence (CVE-2019-3396), and also abused CouchDB and Redis through brute-force or remote code execution. Once deployed, the operators installed XMRig or XMR-Stak Monero miners, established persistence with cron jobs, moved laterally over SSH using available keys and known_hosts, and in some cases used rootkits or Glibc-hooking libraries to hide processes, files, network traffic, and resource usage. Researchers said the activity underscores continued criminal exploitation of long-patched enterprise software vulnerabilities to build stealthy, self-propagating cryptomining botnets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Trend Micro reported that threat actors exploited the Confluence widget connector vulnerability CVE-2019-3396 in April 2019 to deliver a Linux cryptocurrency-mining malware chain with a rootkit component.
Atlassian published an advisory in March 2019 covering two critical Confluence vulnerabilities, including CVE-2019-3396.
Intezer reported that the WatchBog cryptomining botnet had been observed as early as November 2018, operating as a Linux-focused malware campaign that spread by exploiting known vulnerabilities.
Cisco Incident Response observed signs that hosts affected by WatchBog became part of a separate botnet around the same time, complicating the operators' claim that they were merely identifying vulnerabilities.
Based on visits to specific Pastebin links, researchers estimated roughly 4,500 infected endpoints tied to WatchBog, while noting the true total was likely higher due to older infrastructure.
Because WatchBog's HTTPS client did not properly validate SSL/TLS certificates, researchers were able to perform a transparent man-in-the-middle interception and decode bot tasking and victim telemetry.
Intezer identified a new BlueKeep scanning module in WatchBog that probed RDP services on TCP 3389 and returned encrypted lists of potentially vulnerable Windows hosts, indicating collection of targets for later use or resale.
Researchers observed an updated WatchBog spreader that added exploit support for Jira, Exim, Solr, Jenkins, and Nexus Repository Manager 3, along with brute-force and RCE capabilities for CouchDB and Redis.
Intezer found that a new WatchBog version rapidly incorporated new propagation capabilities, adding Jira, Solr, and BlueKeep scanner modules within a 13-day period.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
intezer.com
Open sourcealibabacloud.com
Open sourceblog.talosintelligence.com
Open sourceblog.trendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.