Cloud Threat Landscape
  • Incidents
  • Actors
  • Techniques
  • Defenses
  • Tools
  • Targeted Technologies
  • Posters & Newspapers
  • About
  • RSS
  • STIX
  • Back to wiz.io

Made with 💙 by Wiz

Last Updated: April 3, 2025

Cloud Threat Landscape
/Tools
Tools
/
Sysrv

Sysrv

Tags
CryptominerBotnet
Incidents
Sysrv Apache Druid cryptojacking
References
https://ultimacybr.co.uk/2023-10-04-Sysrv/
Last edited
Apr 27, 2025 11:13 AM

Sysrv is a botnet written in Golang (Go), with worm capabilities that drops XMRig crypto miner onto vulnerable hosts (both Linux and Windows). Iterations have taken advantage of weak passwords and variety of vulnerabilities for different services, including but not limited to: MySQL, Tomcat, Jenkins, WebLogic and WordPress plugins.