The Sysrv-hello cryptomining botnet compromises vulnerable Windows and Linux enterprise servers to deploy XMRig Monero miners and spread to additional systems. Observed since December 2020, it exploits remote code execution vulnerabilities in internet-facing applications and reuses SSH keys recovered from compromised servers for lateral movement. The malware evolved from separate mining and propagation components into a single binary and removes competing cryptocurrency miners from infected hosts. Researchers identified mining wallets associated with F2Pool and Nanopool, indicating illicit cryptocurrency earnings.
Follow-up reporting from Juniper and Lacework highlighted persistence and infrastructure expansion, respectively, extending concerns beyond the botnet’s initial exploitation activity. The combination of application exploitation, credential reuse, and self-propagation exposes organizations to unauthorized compute consumption and broader server compromise. Defenders should prioritize patching exposed applications, investigate unexpected mining processes and resource usage, and audit SSH access. Compromised SSH keys should be revoked or rotated, while affected hosts should be checked for persistence and evidence of lateral movement.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
Alibaba Cloud researchers reported that Sysrv-hello had been active since December 2020. The botnet compromises vulnerable enterprise servers to deploy XMRig Monero miners and self-spreading malware.
Recent Sysrv-hello samples added support for Nanopool and removed support for MineXMR. Juniper identified a Nanopool-associated wallet that collected 8 XMR between March 1 and March 28, valued at approximately $1,700 in the article.
Lacework Labs recovered a Sysrv-hello XMRig configuration containing a Monero wallet associated with F2Pool. The wallet held just over 12 XMR, valued at approximately $4,000 at the time of reporting.
Juniper examined samples collected after the March activity surge and identified exploitation techniques targeting Mongo Express, XML-RPC, SaltStack, Drupal Ajax, ThinkPHP, and XXL-JOB. The findings documented Sysrv-hello's exploitation of remote code execution flaws to spread.
Sysrv-hello evolved from separate miner and worm components into a single binary capable of both cryptocurrency mining and propagation.
A surge in Sysrv-hello activity during March prompted investigations by Lacework Labs and Juniper Threat Labs.
Alibaba Cloud security researchers first spotted the botnet in February and named it Sysrv-hello. The supplied content does not explicitly state the year of discovery.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.