Unidentified Linux 001

First seen
2019-06-10 00:00:00
Malware type
exploit-kit, cryptominer, worm
Profile updated
2026-07-07 14:30:46

Context

According to Cybereason, these scripts have been used in an ongoing campaign exploiting a widespread vulnerability in the Exim MTA: CVE-2019-10149. This attack leverages a week-old vulnerability to gain remote command execution on the target machine, search the Internet for other machines to infect, and initiates a crypto miner.

Exploited vulnerabilities

  • CVE-2019-10149 (vulnerability)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Unidentified 001 (report)
  • cybereason.com — New Pervasive Worm Exploiting Linux Exim Server Vulnerability (report)

External references