Hackers are exploiting vulnerable Jira and Exim servers to infect them with a new variant of the Watchbog Linux Trojan.

Watchbog is a malware used to infect Linux servers by exploiting vulnerabilities .This happened to the Jenkins server during a campaign in May, according to Alibaba Cloud security researchers, as well as to Nexus Repository Manager 3, ThinkPHP and Linux Supervisord as part of an operation since March.
This new variant was discovered by a researcher at Intezer Lab. According to his report, it uses a malicious payload that exploits the vulnerability named CVE-2019-11581, which leads to remote code. It also exploits the Exim flaw named CVE-2019-10149.
According to research conducted by Shodan and BinaryEdge, there are currently more than 1,610,000 vulnerable Exim servers and 54,000 Jira servers that could be affected by the attack. What makes it extremely dangerous is that this variant is not detected by any of the scanning engines on VirusTotal.
The process carried out by Watchbog is simple.
- It introduces a Monero coinminer malware that thwarts users to remove it.
- Then, after it takes over the servers, it will download and execute malicious commands that will launch the final cryptocurrency miner payload.
- The malware will manage to add itself to crontab files, so it can come back and re-infect the system if the user does not find all the.

There is one more fact that makes Watchbog dangerous. In previous versions of the malware, hackers offered their services to remove the virus, promising to send their victims to a “cleaning script.” The note in this variant says that the hackers’ mission is to “keep the internet safe.”
They further claim that the malware will only mine cryptocurrency vulnerable servers and that the purpose is not to compromise other stored data or demand ransom.
