Over 1,500 PostgreSQL Servers Compromised in Fileless Cryptocurrency Mining Campaign

An ongoing attack aims to obtain illegal access and install cryptocurrency miners on exposed PostgreSQL systems.

The activity, according to cloud security company Wiz, is a variation of an intrusion set that was initially discovered by Aqua Security in August 2024 and includes the usage of a malware strain known as PG_MEM. Wiz tracks as JINX-0126, a threat actor who has been implicated in the campaign.

In order to avoid detection by [cloud workload protection platform] solutions that only rely on file hash reputation, the threat actor has since changed and is now using defense evasion techniques like deploying binaries with a unique hash per target and executing the miner payload filelessly, according to researchers Avigayil Mechtinger, Yaara Shriki, and Gili Tikochinski.

According to Wiz, the effort has probably affected more than 1,500 people so far, showing that PostgreSQL instances that are publicly accessible read more about Over 1500 PostgreSQL Servers Compromised in Fileless Cryptocurrency Mining Campaign.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *