Researchers reported that the Sysrv botnet is actively compromising Linux and Windows servers to deploy XMRig Monero miners, using a Golang worm that scans for exposed services, brute-forces weak credentials, and exploits known flaws including CVE-2020-14882 and CVE-2017-11610. The malware has targeted MySQL, Tomcat admin panels, Jenkins, and Oracle WebLogic, then retrieves platform-specific loader scripts and additional worm copies from attacker-controlled infrastructure. On Linux, samples unpack embedded miners from the Golang binary, use TCP port 52013 as a mutex, establish persistence with cron, copy themselves into directories such as /boot and /boot/efi, and in some cases alter /etc/hosts to support mining pool connectivity.

Pull IOCs and campaign context straight into your stack.
9 events from the most recent confirmed update back to the earliest known activity.
Imperva Threat Research observed Sysrv activity in early March 2024 and analyzed a new variant that exploited Apache Struts CVE-2017-9805 and Atlassian Confluence CVE-2023-22527 and CVE-2021-26084. The campaign used a compromised Malaysian academic archive and a Google Sites page to deliver later-stage payloads, including XMRig, while adding SSH propagation, process killing, and stronger obfuscation.
CUJO AI reported that the latest Linux Sysrv ELF binary in its dataset appeared on 20 September 2021.
Uptycs said it identified new variants of the Golang-based wormed cryptominer in June 2021, including samples that embedded XMRig and used the Linux MSR driver to boost mining performance.
Netlab 360 analyzed an update pushed on April 20 that added a new propagation method: a Python script injected iframes into web files on compromised Linux servers to make visitors download BrowserUpdate.exe.
CUJO AI observed that the first obfuscated Sysrv sample appeared in April 2021 and used gobfuscate to hide package and function names.
CUJO AI reported that Sysrv had incorporated the Ignition RCE flaw CVE-2021-3129 into its exploit set by early March 2021, showing the botnet was expanding its propagation methods before the April 2021 updates. This marks a specific escalation in the malware's exploitation capability.
CUJO AI said Sysrv was first publicly mentioned by Intezer at the end of December 2020, bringing the Golang worm and miner campaign into public reporting.
CUJO AI reported that the Sysrv botnet had remained active since late 2020, marking the start of the campaign's observed activity.
Intezer reported that researchers discovered a new Golang worm in early December that spread across Windows and Linux servers to deploy XMRig at scale.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 198 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
intezer.com
Open sourceimperva.com
Open sourcecujo.com
Open sourcecujo.com
Open sourceuptycs.com
Open sourceblog.netlab.360.com
Open sourcedeveloper.aliyun.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.