Tag: Cryptocurrency Mining

Over 1,500 PostgreSQL Servers Compromised in Fileless Cryptocurrency Mining Campaign
News

Over 1,500 PostgreSQL Servers Compromised in Fileless Cryptocurrency Mining Campaign

An ongoing attack aims to obtain illegal access and install cryptocurrency miners on exposed PostgreSQL systems. The activity, according to cloud security company Wiz, is a variation of an intrusion set that was initially discovered by Aqua Security in August 2024 and includes the usage of a malware strain known as PG_MEM. Wiz tracks as JINX-0126, a threat actor who has been implicated in the campaign. In order to avoid detection by [cloud workload protection platform] solutions that only rely on file hash reputation, the threat actor has since changed and is now using defense evasion techniques like deploying binaries with a unique hash per target and executing the miner payload filelessly, according to researchers Avigayil Mechtinger, Yaara Shriki, and Gili Tikochinski. Accordi...
Hackers Exploiting Jenkins Script Console for Cryptocurrency Mining Attacks
News

Hackers Exploiting Jenkins Script Console for Cryptocurrency Mining Attacks

Researchers studying cybersecurity have discovered that attackers may be able to use Jenkins Script Console instances that aren't configured correctly as weapons to carry out illegal actions like mining cryptocurrencies. Attackers can access the '/script' endpoint due to misconfigurations such incorrectly configured authentication procedures, according to a technical write-up released last week by Shubham Singh and Sunil Bharti of Trend Micro. Malicious actors may take advantage of this and cause remote code execution (RCE). Users can run any Groovy script within the Jenkins controller runtime using the Groovy script console included in the well-known continuous integration and delivery (CI/CD) platform Jenkins read more about Hackers Exploiting Jenkins Script Console for Cryptocurr...
8220 Gang Exploits Oracle WebLogic Server Flaws for Cryptocurrency Mining
News

8220 Gang Exploits Oracle WebLogic Server Flaws for Cryptocurrency Mining

By taking advantage of known security holes in the Oracle WebLogic Server, security researchers have added more insight into the cryptocurrency mining operation carried out by the 8220 Gang. "The threat actor uses DLL reflective and process injection, fileless execution techniques, allowing the malware code to run solely in memory and avoid disk-based detection mechanisms," Ahmed Mohamed Ibrahim, Shubham Singh, and Sunil Bharti, researchers at Trend Micro, stated in a new analysis released today. The financially driven actor is being tracked by the cybersecurity firm under the handle Water Sigbin. This actor is known to weaponize Oracle WebLogic Server vulnerabilities like CVE-2017-3506, CVE-2017-10271, and CVE-2023-21839 for initial access and to drop the miner payload using a mult...
New Malware Targets Exposed Docker APIs for Cryptocurrency Mining
News

New Malware Targets Exposed Docker APIs for Cryptocurrency Mining

Researchers studying cybersecurity have discovered a new malware campaign that aims to send bitcoin miners and other payloads via publicly accessible Docket API endpoints. In a report released last week, cloud analytics platform Datadog stated that among the tools used were a remote access tool with the ability to download and run other dangerous applications as well as a utility to spread the virus via SSH. Tactical similarities between the effort and Spinning YARN, an earlier initiative that targeted incorrectly configured Apache Hadoop YARN, Docker, Atlassian Confluence, and Redis services for cryptojacking, have been found during campaign analysis. The threat actors focus on Docker servers that have exposed ports (port number 2375) at the beginning of the assault to launch a ...
New Migo Malware Targeting Redis Servers for Cryptocurrency Mining
News

New Migo Malware Targeting Redis Servers for Cryptocurrency Mining

A new malware campaign has been noticed that aims to mine cryptocurrency on compromised Linux machines by first targeting Redis servers. According to a technical analysis by Cado security researcher Matt Muir, "this particular campaign involves the use of a number of novel system weakening techniques against the data store itself." The virus known as Migo, a Golang ELF program with compile-time obfuscation and persistence on Linux systems, is what makes the cryptojacking assault possible. The campaign was discovered, according to the cloud security provider, after it saw a "unusual series of commands" directed at its Redis honeypots, which are designed to weaken security read more New Migo Malware Targeting Redis Servers for Cryptocurrency Mining. Get up to date on the latest ...
Warning: Poorly Secured Linux SSH Servers Under Attack for Cryptocurrency Mining
News

Warning: Poorly Secured Linux SSH Servers Under Attack for Cryptocurrency Mining

Malicious actors are using weakly secured Linux SSH servers as a target to install dictionary attack tools and port scanners in an attempt to take down other weaker servers and use them as part of a network for distributed denial-of-service (DDoS) assaults and cryptocurrency mining. "In a report released on Tuesday, the AhnLab Security Emergency Response Center (ASEC) stated that threat actors have the option to install solely scanners and then sell the compromised IP and account credentials on the dark web." Using a method known as dictionary attack, adversaries attempt to guess a server's SSH credentials by sifting through a list of frequently used username and password combinations. If the brute-force attack is successful, the threat actor will use other software, such as scan...