Over 1,500 PostgreSQL Servers Compromised in Fileless Cryptocurrency Mining Campaign
An ongoing attack aims to obtain illegal access and install cryptocurrency miners on exposed PostgreSQL systems.
The activity, according to cloud security company Wiz, is a variation of an intrusion set that was initially discovered by Aqua Security in August 2024 and includes the usage of a malware strain known as PG_MEM. Wiz tracks as JINX-0126, a threat actor who has been implicated in the campaign.
In order to avoid detection by [cloud workload protection platform] solutions that only rely on file hash reputation, the threat actor has since changed and is now using defense evasion techniques like deploying binaries with a unique hash per target and executing the miner payload filelessly, according to researchers Avigayil Mechtinger, Yaara Shriki, and Gili Tikochinski.
Accordi...






