Security researchers have uncovered a new Watchbog malware variant affecting Jira and Exim servers. It was found that the malware was exploiting recent vulnerabilities in these servers. The vulnerabilities were code execution flaws in both Jira and Exim servers.
It is speculated that over 1.6 million unpatched Exim servers are vulnerable to the new Watchbog variant. Likewise, more than 54,000 unpatched Jira servers are also defenseless against the trojan.
The big picture
Worth noting
A malicious script associated with the new Watchbog also had a contact note, on top of delivering a Monero miner. According to BleepingComputer which covered this new development of Watchbog, the creators behind this malware wanted to ‘keep the internet safe’ in the malware campaign.
“They also say that the malware will only mine for cryptocurrency on compromised servers, with no intention of tampering with the stored data in any way or asking for a ransom,” BleepingComputer reported.
Publisher