Windows servers running IIS 6.0 targeted by crypto-mining hackers

April 16, 2018

HACKERS ARE EXPLOITING previously discovered – and patched – IIS 6.0 vulnerability to take control of Windows servers and mine Electroneum cryptocurrency.

First identified by two researchers in China in March 2017, the CVE-2017-7269 vulnerability allows hackers to install a malware strain on the IIS 6.0 service.

When they made the discovery, the exploit had been in circulation for around nine months. Crooks began tapping into the vulnerability in June 2016.

