Security News

Jenkins project's Confluence server hacked to mine Monero
2021-09-07 15:46

Hackers exploiting the recently disclosed Atlassian Confluence remote code execution vulnerability breached an internal server from the Jenkins project. While the attack is concerning because Jenkins is a popular open-source server for automating parts of software development, there is no reason that the project releases, plugins, or code have been impacted.

Splunk spots malware targeting Windows Server on AWS to mine Monero
2021-08-10 07:04

Data analysis firm Splunk says it's found a resurgence of the Crypto botnet - malware that attacks virtual servers running Windows Server inside Amazon Web Services. Splunk's Threat Research Team posted its analysis of the attack on Monday, suggesting it starts with a probe for Windows Server instances running on AWS, and seeks out those with remote desktop protocol enabled.

Crackonosh virus mined $2 million of Monero from 222,000 hacked computers
2021-06-27 20:00

A previously undocumented Windows malware has infected over 222,000 systems worldwide since at least June 2018, yielding its developer no less than 9,000 Moneros in illegal profits. Dubbed "Crackonosh," the malware is distributed via illegal, cracked copies of popular software, only to disable antivirus programs installed in the machine and install a coin miner package called XMRig for stealthily exploiting the infected host's resources to mine Monero.

Monero-mining botnet targets orgs through recent MS Exchange vulnerabilities
2021-04-22 10:49

The recent Microsoft Exchange Server vulnerabilities might have initially been exploited by a government-backed APT group, but cybercriminals soon followed suit, using them to deliver ransomware and grow their botnet. One perpetrator of the latter activities is Prometei, a cross-platform, modular Monero-mining botnet that seems to have flown under the radar for years.

New Malware Hijacks Kubernetes Clusters to Mine Monero
2021-02-03 20:50

Researchers have discovered never-before-seen malware, dubbed Hildegard, that is being used by the TeamTNT threat group to target Kubernetes clusters. Eventually, they warn, TeamTNT may launch a more large-scale cryptojacking attack via Kubernetes environments or steal data from applications running in Kubernetes clusters.

New worm turns Windows, Linux servers into Monero miners
2020-12-30 09:40

A newly discovered and self-spreading Golang-based malware has been actively dropping XMRig cryptocurrency miners on Windows and Linux servers since early December. The C2 server is used to host the bash or PowerShell dropper script, a Golang-based binary worm, and the XMRig miner deployed to surreptitiously mine for untraceable Monero cryptocurrency on infected devices.

PGMiner, Innovative Monero-Mining Botnet, Surprises Researchers
2020-12-11 19:41

An innovative Linux-based cryptocurrency mining botnet has been uncovered, which exploits a disputed PostgreSQL remote code-execution vulnerability to compromise database servers. The miner takes a fileless approach, deleting the PostgreSQL table right after code launch, researchers said: PGMiner clears the "Abroxu" table if it exists, creates a new "Abroxu" table with a text column, saves the malicious payload to it, executes the payload on the PostgreSQL server and then clears the created table.

Blue Mockingbird Monero-Mining Campaign Exploits Web Apps
2020-05-07 21:01

A Monero cryptocurrency-mining campaign has emerged that exploits a known vulnerability in public-facing web applications built on the ASP.NET open-source web framework. The campaign has been dubbed Blue Mockingbird by the analysts at Red Canary that discovered the activity.

T-Mobile US hacked, Monero wallet app infected, public info records on 1.2bn people leak from database...
2019-11-23 10:06

...OnePlus also compromised, and much more Roundup Time for another roundup of all the security news that's fit to print and that we haven't covered yet.…

Official Monero site delivers malicious cash-grabbing wallet
2019-11-21 12:18

If you downloaded the Monero command line wallet recently, check it before using it.