Tag: Cryptojacking Campaign

Cryptojacking Campaign Exploits DevOps APIs Using Off-the-Shelf Tools from GitHub
News

Cryptojacking Campaign Exploits DevOps APIs Using Off-the-Shelf Tools from GitHub

Researchers studying cybersecurity have uncovered a new cryptojacking campaign that aims to generate bitcoins illegally by targeting publicly available DevOps web servers, including those connected to Docker, Gitea, and HashiCorp Consul and Nomad. The attackers are delivering the miner payload by taking advantage of numerous known vulnerabilities and misconfigurations, according to cloud security company Wiz, which is monitoring the activity under the name JINX-0132. Researchers Gili Tikochinski, Danielle Aminov, and Merav Bar noted in a study shared with The Hacker News that this campaign is noteworthy since it represents what they believe to be the first publicly documented case of Nomad misconfigurations being exploited as an attack vector in the field. The fact that the malic...
Exposed Docker APIs Under Attack in ‘Commando Cat’ Cryptojacking Campaign
News

Exposed Docker APIs Under Attack in ‘Commando Cat’ Cryptojacking Campaign

A highly skilled cryptojacking effort known as Commando Cat is targeting exposed Docker API endpoints on the internet. In a recent analysis released today, Cado security experts Nate Bill and Matt Muir stated, "The campaign deploys a benign container generated using the Commando project." "The attacker escapes this container and runs multiple payloads on the Docker host." This is the second campaign of its kind that has been found in as many months; it is thought to have been underway since the beginning of 2024. The cloud security company also revealed details on another activity cluster in mid-January that targets susceptible Docker systems read more Exposed Docker APIs Under Attack in Commando Cat Cryptojacking Campaign. Get up to date on the latest cybersecurity news and enha...
SCARLETEEL Cryptojacking Campaign Exploiting AWS Fargate in Ongoing Campaign
News

SCARLETEEL Cryptojacking Campaign Exploiting AWS Fargate in Ongoing Campaign

An continuing sophisticated attack effort known as SCARLETEEL continues to target cloud settings, with threat actors currently focusing on Amazon Web Services (AWS) Fargate. According to a new report from Sysdig security researcher Alessandro Brucato, "Cloud environments are still their primary target, but the tools and techniques used have adapted to bypass new security measures, along with a more resilient and stealthy command and control architecture." The cybersecurity firm originally revealed SCARLETEEL in February 2023, describing a complex attack chain that resulted in the theft of confidential information from AWS infrastructure read more SCARLETEEL Cryptojacking Campaign Exploiting AWS Fargate in Ongoing Campaign. Stay informed with the best cybersecurity news and raise ...