Tag: cryptocurrency miners

Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner
News

Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner

The deployment of cryptocurrency miners and information thieves is the result of a continuous phishing campaign that targets French-speaking corporate environments with phony resumes. According to a study published with The Hacker News by Securonix researchers Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee, the campaign leverages highly obfuscated VBScript files that are sent through phishing emails under the appearance of resume/CV materials. In order to maximize profits, the malware uses a multifunctional toolkit that includes data exfiltration, credential theft, and Monero cryptocurrency mining. The cybersecurity firm has dubbed the action FAUX#ELEVATE. The campaign is notable for abusing reputable infrastructure and services, including mail, Moroccan WordPress websites h...
Over 1,500 PostgreSQL Servers Compromised in Fileless Cryptocurrency Mining Campaign
News

Over 1,500 PostgreSQL Servers Compromised in Fileless Cryptocurrency Mining Campaign

An ongoing attack aims to obtain illegal access and install cryptocurrency miners on exposed PostgreSQL systems. The activity, according to cloud security company Wiz, is a variation of an intrusion set that was initially discovered by Aqua Security in August 2024 and includes the usage of a malware strain known as PG_MEM. Wiz tracks as JINX-0126, a threat actor who has been implicated in the campaign. In order to avoid detection by [cloud workload protection platform] solutions that only rely on file hash reputation, the threat actor has since changed and is now using defense evasion techniques like deploying binaries with a unique hash per target and executing the miner payload filelessly, according to researchers Avigayil Mechtinger, Yaara Shriki, and Gili Tikochinski. Accordi...
Rust-Based P2PInfect Botnet Evolves with Miner and Ransomware Payloads
News

Rust-Based P2PInfect Botnet Evolves with Miner and Ransomware Payloads

P2PInfect, a peer-to-peer malware botnet, has been discovered to target cryptocurrency miners and improperly setup Redis servers with ransomware. This development indicates that the threat has evolved from what seemed to be a financially motivated operation running a dormant botnet to one with defined objectives. According to a report released this week by Cado Security, the malware author's ongoing efforts to profit from their unauthorized access and spread the network further are demonstrated by the most recent updates to the crypto miner, ransomware payload, and rootkit elements. The malware is still worming its way across the internet read more about Rust-Based P2PInfect Botnet Evolves with Miner and Ransomware Payloads. Get up to date on the latest cybersecurity news and enh...