Cisco IR responded to an incident involving the Watchbog cryptomining botnet. The attackers were able to exploit CVE-2018-1000861 to gain a foothold and install the malware. The malware relied heavily on Pastebin for command and control (C2) and operated openly. Cisco IR found signs of hosts becoming a part of a separate botnet around the time of the attack. This raises serious doubts about the “positive” intentions of this adversary. The attackers did not practice particularly strong operational security. The attack was still relatively simple to uncover.”]
Source: https://blog.talosintelligence.com/2019/09/watchbog-patching.html

