SYSRV-HELLO MINER
SYSRV
MALWARE
ECRIME
Threat IntelligenceMalwareMarch 19, 202515 min read

Sysrv-Hello Miner: Threat Intelligence Profile

Cryptomining botnet

Scroll

Sysrv-Hello Miner (also known as Sysrv, Sysrv-Hello) is a malware active since 2020. Cryptomining botnet. Key characteristics include: Go-based, multi-vulnerability exploitation, XMRig mining, worm propagation, Linux/Windows.

Overview & Background

Cryptomining botnet. First identified in 2020, this threat is attributed to eCrime.

Threat Assessment

Sysrv-Hello Miner remains an active threat. Organizations should implement detection rules and monitor for indicators associated with this malware.

Technical Analysis

Sysrv-Hello Miner employs the following capabilities and techniques:

MITRE ATT&CK Mapping

TacticTechniqueUsage
Initial AccessT1566.001 Phishing AttachmentCommon delivery vector
ExecutionT1204.002 Malicious FileUser-triggered execution
PersistenceT1547.001 Registry Run KeysAutostart persistence
Defense EvasionT1027 Obfuscated FilesPayload obfuscation
C2T1071.001 Web ProtocolsHTTP/HTTPS C2

Detection & Defense

Defend Against Sysrv-Hello Miner

Mjolnir Security provides detection and response capabilities against Sysrv-Hello Miner and similar threats.

Threat DetectionIncident ResponseThreat HuntingMDR ServicesThreat Intelligence
  • Proactive Threat Hunting Hunt for Sysrv-Hello Miner indicators and TTPs within your environment.
  • Threat Intelligence Monitor Sysrv-Hello Miner campaigns and infrastructure changes.
  • 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: March 19, 2025