216.73.216.6

CoinMiner Attacks Exploiting GeoServer Vulnerability

· Published 08/08/2025 17:08 · Modified 10/08/2025 21:39

Export JSON

Essential information

Published
08/08/2025 17:08
Modified
10/08/2025 21:39
Tags
2025-08-08 CVE-2024-36401 bash coinminer condi geoserver goreverse mirai monero netcat powershell remote code execution sidewalk xmrig
Related entities
4 observables, 6 techniques (mitre), 1 others

Description

A critical vulnerability () in has been actively exploited by threat actors to install malware. The attacks target both Windows and Linux environments with unpatched installations. In South Korea, attackers exploited the vulnerability to execute commands, installing for remote access and for cryptocurrency mining. The attack process involves downloading malicious scripts, terminating competing miners, and establishing persistence through Cron jobs. The threat actors use pool.supportxmr.com for mining coins and can potentially perform additional malicious activities using the installed .

External references