HomeSecurityXWiki: RCE vulnerability used to deliver cryptominer

XWiki: RCE vulnerability used to deliver cryptominer

A critical remote code execution (RCE) vulnerability in XWiki is being actively exploited by cybercriminals to deploy cryptocurrency mining malware (cryptominer) on compromised servers. XWiki is a popular open source wiki platform.

XWiki RCE cryptominer vulnerability

The vulnerability, tracked as CVE-2025-24893, allows unauthorized attackers to insert malicious templates and execute arbitrary code, completely bypassing authentication.

This discovery highlights the growing threat to web applications, where real-world attacks often outpace official notifications from organizations such as CISA's Known Exploitable Vulnerabilities (KEV) list

See also: Mem3nt0 Mori hackers use Chrome zero-day

VulnCheck reported exploitation of the vulnerability in question, based on data from their Canary network, which simulates vulnerable systems to detect attacks.

Unlike previous reports from Cyble, Shadow Server, and CrowdSec that noted simple exploit attempts, VulnCheck's observations reveal a sophisticated two-stage attack chain originating from an IP address in Vietnam.

The vulnerability, added to VulnCheck KEV in March 2025, involves template injection in XWiki's SolrSearch endpoint, allowing attackers to execute Groovy scripts to execute commands.

XWiki: RCE vulnerability used to deliver cryptominer

XWiki RCE Vulnerability: How does the attack work?

The attack unfolds in two phases, at least 20 minutes apart, to avoid detection.

See also: CISA: Fix exploited vulnerability in WSUS

In the initial request, the attackers send a URL-encoded GET to the SolrSearch endpoint, injecting an asynchronous Groovy payload that uses wget to download a downloader script (named x640) from a command and control (C2) server at 193.32.208.24:8080.

This script is stored in /tmp/11909 on the target system. The payload mimics normal browser traffic with a Firefox user agent.

About 20 minutes later, a second request executes the staged file by calling bash at /tmp/11909. The downloader then downloads two additional scripts, x521 and x522, which are piped directly to bash for execution, VulnCheck said.

These scripts manage the delivery of the payload: x521 creates directories in /var/tmp, downloads the tcrond coinminer from the same C2, and sets execution permissions.

Meanwhile, x522 cleans up the environment, killing competing miners like xmrig and kinsing, clears the history logs, and starts tcrond with a configuration that points to auto.c3pool.org on port 80.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

XWiki: RCE vulnerability used to deliver cryptominer

The miner (UPX-packed for obfuscation) uses a address Monero wallet for payments, indicating a low-complexity but persistent operation.

See also: HashiCorp Vault: Vulnerabilities allow DoS attacks and authentication bypass

All traffic is traced back to the address 123.25.249.88, which has been flagged in multiple AbuseIPDB reports for abusive activity.

Protection

Defenders can use these indicators to look for similar activity on networks. The exploit uses transfer.sh to host payloads, a common tactic in cryptojacking campaigns.

Organizations using XWiki should immediately implement version 15.10.6 or later, monitor for strange wget traffic , and check for these indicators of violation (IOCs).

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS