Unidentified Linux 001
- First seen
- 2019-06-10 00:00:00
- Malware type
- exploit-kit, cryptominer, worm
- Profile updated
- 2026-07-07 14:30:46
Context
According to Cybereason, these scripts have been used in an ongoing campaign exploiting a widespread vulnerability in the Exim MTA: CVE-2019-10149. This attack leverages a week-old vulnerability to gain remote command execution on the target machine, search the Internet for other machines to infect, and initiates a crypto miner.
Exploited vulnerabilities
- CVE-2019-10149 (vulnerability)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Unidentified 001 (report)
- cybereason.com — New Pervasive Worm Exploiting Linux Exim Server Vulnerability (report)