Exim Mining Worm
A new unnamed worm has been observed exploiting the recently disclosed Exim vulnerability, CVE-2019-10149, to install cryptocurrency miners on affected mail servers.
Summary
A new unnamed worm has been observed exploiting the recently disclosed Exim vulnerability, CVE-2019-10149, to install cryptocurrency miners on affected mail servers.
Affected platforms
The following platforms are known to be affected:
Threat details
The worm identifies new target servers using a Python-based port scanning module. It will then execute an initial script to install itself on the new servers. Several scripts are then downloaded and executed to create cronjobs in order to maintain persistence and download other payloads. The worm will also add its own RSA authentication key to the server's root directory.
At the time of publication, only a cryptocurrency mining module has been seen being installed by the worm, although it is possible that other payloads may be installed in the future.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
Exim released an update to address CVE-2019-10149. Organisations are encouraged to apply this update immediately. Additionally, to prevent and detect an infection, ensure that:
|
CVE Vulnerabilities
Last edited: 14 February 2020 2:45 pm