Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

How a Botnet of Thousands of Servers Mined Cryptocurrency: The 2017 BondNet Incident

The 2017 BondNet operation turned thousands of compromised Windows servers into Monero miners while using a WMI backdoor for persistence, command execution and botnet expansion.
From TheFinanceBase Team4 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

BondNet was a criminal network that compromised Windows servers, installed a Monero miner and a WMI-based backdoor, and used some infected machines to expand and manage the operation. GuardiCore’s findings, reported by SecurityWeek on May 4, 2017, counted more than 15,000 compromised machines and estimated operator proceeds at about $1,000 per day at that time. Those figures describe the 2017 report—not BondNet’s current size or activity.

What BondNet was and what the 2017 report found

GuardiCore described BondNet as a botnet built from hacked Windows Server systems. Its most visible purpose was cryptocurrency mining, primarily Monero, but the malware also provided remote control that could have supported more damaging actions.

According to GuardiCore as quoted by SecurityWeek on May 4, 2017, the operation appeared to have been active since December 2016. The report said more than 15,000 machines had been compromised, while about 2,000 servers contacted the command-and-control infrastructure on a typical day. GuardiCore also estimated roughly 500 machines were added daily and a similar number removed from the active list. These were contemporary estimates, not an ongoing measurement.

How attackers obtained server access

The campaign reportedly combined public exploits with weak or exposed credentials. Its targets were Windows Server machines and services reachable from the internet. GuardiCore’s examples included:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Mining Rig Case with 6 Pack Fan, Miner Case Support 6/8 GPU 27 Inches Mining Case for Crypto Coin Currency Bitcoin ETH/ETC/ZEC (Suitable for ATX Power Supply, Motherboard)
  • 【Cold plate full baking paint to prevent rust, anti-static effect. The fan of the product is double ball fan, 6 PCS new violent fan】
  • 【Supports up to 6 / 8 330mm long graphics cards】
  • 【The mining case with 2 USB Ports , 5 PCS LED wire and USB connect wire. It is designed for cryptocurrency mining—Litecoin, Dogecoin, Ethereum, Ripple, Zerocoin etc.】
  • 【Safe Design】: Ventilation holes designed on both sides can ensure better heat dissipation for the power supply and motherboard when the device is running, and extend the life of the device.
  • 【Supports Motherboard type】: ATX/M-ATX/Mini ATX. Hard disk type: 3.5"HDD/2.5" SSD*2. Power supply: Support ATX PSU*1
  • phpMyAdmin configuration weaknesses
  • Vulnerabilities associated with JBoss and Oracle WebLogic
  • Exposed ElasticSearch and MSSQL services
  • Apache Tomcat and other internet-facing applications
  • Oracle Web Application Testing Suite and related enterprise software

This list records the examples named in the 2017 incident report; it is not a current vulnerability advisory. The common feature was an externally reachable service that could be exploited or entered with credentials that were too weak or exposed.

What happened after a server was compromised

Installing the miner and backdoor

The attackers reportedly used Visual Basic files to install two key components: a cryptocurrency miner and a remote-access Trojan. Mining converted the server’s processor time and electricity into Monero for the operators. The backdoor gave the attackers a way to issue commands and maintain control.

Rank #2
AAAwave 12GPU Mining Rig Frame - Sluice V2 Open Frame Case - Black
  • Durable: Constructed with high-quality metal, this mining frame ensures long-lasting durability and full protection for your GPU mining rig and electronic devices.
  • Efficient Cooling: Designed for enhanced air convection, this mining case maximizes heat dissipation, helping to extend the service life of your GPUs during intensive mining operations.
  • Professional Build: Features non-slip rubber feet and EVA foam on the crossbar to prevent damage to your graphic cards. Perfect for securing and protecting your GPUs in a mining rig setup.
  • Stackable Design: This mining frame supports stackable configurations, allowing you to expand your GPU mining setup easily with additional mining cases or stacking brackets (sold separately).
  • Stable and Secure: Equipped with rubber feet, this mining case prevents shaking and moving, keeping your mining rig stable during operation.

Using WMI for command execution

The backdoor relied on Windows Management Instrumentation (WMI), a native Windows management facility, to execute commands remotely. The report said attackers could enable the Guest account and connect through Remote Desktop Protocol (RDP), Server Message Block (SMB) or Remote Procedure Call (RPC). That capability made the infection more than a stand-alone mining program.

Surviving reboots

Scheduled tasks were used to restart miners after a server reboot. Persistence matters to a mining operation because an interrupted process stops earning; an automated task reduces the need for the operator to reconnect manually.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
8GPU Mining Rig Frame, Steel Open Air Miner Mining Computer Frame Rig Case for Crypto Coin Currency Bitcoin ETH ETC ZEC Mining Accessories Tools - Frame Only, Fans & GPU is not Included
  • 6/8 SLOTS - Support to 6/8 GPU . (GPU is not included).
  • MATERIAL - The open air mining frame case is made up of the highest quality stainless steel material, strong, durable and available. Fully protecting your GPU and eectronic device.
  • PERFECT DESIGN - Professional design for mining rig frame, accelerating the air convection, super cooling design for heat dissipation. Enough space reserved between the graphics cards.
  • EASY TO INSTALL - This mining case is easy to install and is with strong structure. Keep all cables clean and organized, along with everything in your mining machine.For installation steps, please refer to the user manual
  • NOTICE - This mining rig frame is the Frame Only, not includes Fans or other CPU, GPU, PSU, Motherboards, Cables. If you are not 100% satistifed with this Miner, please feel free to contact us, we will offer you a satisfactory soluiton within 24 hours.

How the botnet supported its own expansion

Not every infected machine had the same job. GuardiCore described a division of labor:

Botnet role Function described in the 2017 report
Scanning nodes Looked for additional vulnerable or weakly protected targets using a TCP port scanner.
File-hosting nodes Stored malware files that other compromised servers could download.
Command-and-control servers Coordinated infected machines and issued instructions; the report mentions a modified open-source Go HTTP server.
Mining victims Ran the Monero-mining payload and consumed their owners’ computing resources and electricity.

This structure explains why the incident was a botnet rather than simply a collection of hijacked computers. Compromised servers helped find victims, distribute components, communicate with operators and perform the revenue-generating work.

Rank #4
Bitcoins Miner Solo Lottery Miner 2.4G WiFi SHA-256 BM1366 Latest Upgrade Model V7 1TH/S Crypto BTC Miner Asic Chip Home Use Machine
  • High Performance ASIC Mining Chip: The device is equipped with an advanced BM1366 ASIC mining chip, featuring a hash rate between 900GH/S and 1100GH/S; Its featuring a 5nm ASIC chip performance for cryptocurrency mining; With the utilization of advanced technology and high quality components, this mining machine ensures high efficiency and long term stable operation
  • Support Multiple Cryptocurrency: The mining machine supports multiple cryptocurrencies that using the SHA-256 algorithm, including BTC, BCH, BSV, DGB, BCD, B2X, SBTC, BCHC, BTX, up to 42 others
  • Mining Modes: The bitcoins miner LV07 is a compact, and portable cryptocurrency mining machine; Is compatible with various mining modes, including SOLO, PPLNS, PPS, PROP, allowing users to choose the most suitable method for their mining needs; The main mining mode of our LV07 is SOLO, there is a chance to win 3.125 BTC every 10 minutes as a lotto device
  • 2.4G WiFi Connectivity: The built-in 2.4G WiFi module supports wireless connection, allowing users to easily connect the miner to their home network; Remote monitoring and management can be achieved without complicated wiring operations, which greatly enhances the convenience of use
  • Low Power and Low Noise: This lottery miner is optimised for size, noise and power consumption; Its compact body and micro-quiet technology allow the device to easily fit at home without disrupting daily life; The low power consumption design reduces the user's operating cost

How much money did mining generate?

GuardiCore estimated proceeds at around $1,000 per day and more than $25,000 per month, as reported in 2017. The figures were estimates based on the operation observed then and should not be read as a current valuation or a guaranteed return. Profit came from shifting the costs—electricity, hardware wear and lost capacity—to the owners of the compromised servers.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why a “minor” mining infection could become a major breach

Cryptocurrency mining may first appear as a performance or electricity problem. A miner can increase processor use, slow applications and raise an organization’s power bill. BondNet’s backdoor changed the risk calculation because the same access could be used for broader intrusion.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“While organizations can treat this as a minor issue of increased electric bills, with relatively simple modifications this backdoor is capable of taking complete control of thousands of victim machines, many of which contain sensitive information like mail servers. Today’s mining may easily become a ransomware campaign, data exfiltration or lateral movement inside the victim’s network,”

—GuardiCore, quoted in SecurityWeek, May 4, 2017.

That statement is a risk assessment, not proof that every BondNet victim suffered ransomware, data theft or lateral movement. It identifies what the installed remote-control capability could enable if the operators changed objectives.

What the incident teaches defenders

  • Internet exposure increases attack surface: Publicly reachable administration and application services need strict access controls and timely patching.
  • Credential hygiene matters: Weak, reused or exposed passwords can provide an alternative route when an exploit is unavailable.
  • Persistence deserves investigation: Unexpected scheduled tasks, new Guest-account activity and unexplained WMI execution are important indicators on Windows servers.
  • Separate server roles: A host that can scan, download files and execute commands can help an intruder expand beyond the initial infection.
  • Look beyond CPU usage: A miner may be the visible symptom of a backdoor with access to sensitive services and data.

What is—and is not—known today

The BondNet figures belong to GuardiCore’s 2017 investigation as relayed by SecurityWeek. The report does not establish the botnet’s present size, whether it remains active, or what it earns now. Its lasting value is as an incident model: attackers can turn exposed servers into mining workers while simultaneously building an infrastructure for scanning, malware delivery and remote control.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.