Cryptojacking Campaign Exploits DevOps APIs Using Off-the-Shelf Tools from GitHub
Researchers studying cybersecurity have uncovered a new cryptojacking campaign that aims to generate bitcoins illegally by targeting publicly available DevOps web servers, including those connected to Docker, Gitea, and HashiCorp Consul and Nomad.
The attackers are delivering the miner payload by taking advantage of numerous known vulnerabilities and misconfigurations, according to cloud security company Wiz, which is monitoring the activity under the name JINX-0132.
Researchers Gili Tikochinski, Danielle Aminov, and Merav Bar noted in a study shared with The Hacker News that this campaign is noteworthy since it represents what they believe to be the first publicly documented case of Nomad misconfigurations being exploited as an attack vector in the field.
The fact that the malic...



