Attackers exploited multiple publicly disclosed pre-authentication vulnerabilities in internet-exposed enterprise products to install Monero-mining malware on both Windows and Linux systems. Observed targets included Apache HTTP Server, Atlassian Confluence, F5 BIG-IP, VMware vCenter, and Oracle WebLogic Server, with exploitation attempts seen in the wild through honeypots. The operation abused trusted cloud platforms GitHub and Netlify to host delivery scripts and miner payloads, helping the malware blend into normal HTTPS traffic before the hosted content was removed.
On Windows, the malware used batch scripts to profile infected hosts, download XMRig and supporting components, establish persistence, and run the miner as a background service. On Linux, shell scripts killed high-CPU processes, removed competing miners, fetched multiple binaries and configuration files, and launched mining with nohup. The campaign highlighted how public proof-of-concept exploits, unpatched exposed servers, and the use of legitimate hosting services combined to sustain large-scale cryptojacking activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Trend Micro notified GitHub and Netlify about the malicious activity, and both platforms took down the attacker accounts hosting the mining infrastructure. This disrupted the campaign's use of legitimate hosting services.
The campaign abused GitHub and Netlify as distribution points for malicious scripts, miner binaries, and configuration files. Trend Micro reported Windows batch scripts and Linux shell scripts downloading XMRig-related payloads and configs from attacker-controlled repositories and CDN locations.
Trend Micro observed in-the-wild exploitation attempts using pre-authentication vulnerabilities in products including Apache HTTP Server, Atlassian Confluence, F5 BIG-IP, VMware vCenter, and Oracle WebLogic Server to deploy Monero-mining malware. The malware targeted both Windows and Linux systems.
The Apache HTTP Server Project released official fixes for CVE-2021-41773 and the bypass issue tracked as CVE-2021-42013. These vulnerabilities were later among those exploited in the mining campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.