GeoServer Security Flaw Unleashes Crypto Miners, Botnets, and Backdoor Chaos
A critical remote code execution bug in OSGeo GeoServer GeoTools (CVE-2024-36401) is being exploited to deliver cryptocurrency miners, botnet malware, and the SideWalk backdoor. The flaw targets IT service providers, tech companies, and government entities worldwide.

Hot Take:
Looks like GeoServer GeoTools took “mining for data” a bit too literally! Who knew geospatial data could dig up so much trouble? If only it could map its way out of this mess!
Key Points:
- Critical remote code execution bug (CVE-2024-36401) with a CVSS score of 9.8
- Exploited to deliver cryptocurrency miners, botnets, and a backdoor called SideWalk
- Targets include IT service providers in India, tech companies in the U.S., government entities in Belgium, and telecoms in Thailand and Brazil
- Notable attack chain involves a Chinese APT41 group deploying an advanced Linux backdoor
- CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog in mid-July 2024
Already a member? Log in here