A cryptocurrency-mining campaign dubbed RubyMiner attempted to compromise web servers across 30% of networks worldwide within 24 hours, according to Check Point Research’s January 2018 report. The reportedly lone attacker exploited older vulnerabilities affecting PHP, Microsoft IIS, and Ruby on Rails to deploy a modified XMRig miner for Monero. Approximately 700 servers had reportedly joined the attacker’s mining pool by publication, generating about $540; the 30% figure described attempted attacks, not confirmed infections.
The infection chain removed existing cron jobs and installed an hourly task that downloaded and executed malicious content disguised as a robots.txt file. The campaign demonstrated how long-known vulnerabilities in publicly exposed servers could enable unauthorized mining and recurring malicious execution. Defenders should prioritize patching internet-facing web servers, investigate unexpected mining processes and scheduled-task changes, and review suspicious downloads masquerading as robots.txt.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
In early 2018, a reportedly lone attacker attempted to compromise PHP, Microsoft IIS, and Ruby on Rails servers across 30% of worldwide networks within 24 hours, exploiting older vulnerabilities to deploy a modified XMRig Monero miner. Approximately 700 servers had joined the mining pool by the time of the report, generating about $540.
A 2013 attack exploiting a Ruby on Rails vulnerability used lochjol[.]com, a domain later observed in the RubyMiner campaign. Researchers could not establish a connection or common attacker between the two attacks.
Check Point reported that RubyMiner removed existing cron jobs and installed an hourly task that downloaded internetresearch[.]is/robots.txt and executed its contents with bash. The report also detailed exploitation of CVE-2013-0156 and published attack infrastructure indicators and payload hashes.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.