Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

Beyond Hype: 55% of Spanish Companies Prove AI’s Impact on Decisions

Trump administration’s sanctions on Harvard international students hurt global appeal

Hackers use Tiktok videos to distribute Vidar and Stealc malware via Clickfix techniques

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » Over 1,500 PostgreSQL servers have been compromised in a fireless cryptocurrency mining campaign
Identity

Over 1,500 PostgreSQL servers have been compromised in a fireless cryptocurrency mining campaign

userBy userApril 1, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

April 1, 2025Ravi LakshmananCrypto Jacking/Cloud Security

Exposed PostgreSQL instances are the target of ongoing campaigns designed to gain unauthorized access and deploy cryptocurrency miners.

Cloud security company Wiz said the activity was a variant of the intrusion set initially flagged by Aqua Security in August 2024, including the use of a malware stock called PG_MEM. This campaign is attributed to the threatening actor Wiz track as Jinx-0126.

“Threatening actors can then evolve and implement defensive evasion techniques such as deploying binary with a unique hash for each target, and may avoid detection, such as running minor payloads fireless. [cloud workload protection platform] A solution that relies solely on the reputation of hash,” said researchers Avigayil Mechtinger, Yaara Shriki, and Gili Tikochinski.

Cybersecurity

Wiz also revealed that the campaign likely claims more than 1,500 victims to date.

The most distinctive aspect of the campaign is the abuse of copying from a program SQL command that executes any shell command on the host.

The access gained by the successful exploitation of weakly configured PostgreSQL services is used to carry out pre-recon and drop Base64 encoded payloads. It’s actually a shell script that kills competing cryptocurrency miners and drops a binary named PG_Core.

Also downloaded to the server is a postmaster of an obfuscated Golang binary codename that mimics a legitimate PostgreSQL multi-user database server. It is designed to use Cron jobs to set up persistence on a host, increase privileges and create new roles, and write another binary called CPU_HU to disk.

Cybersecurity

CPU_HU downloads the latest version of Xmrig Miner from GitHub and downloads FILLESSLY via the known Linux Filless Technique called MEMFD.

“The threat actors assign unique mining workers to each victim,” Wiz said. “Each wallet had around 550 workers. In total, this suggests that the campaign could have leveraged over 1,500 compromised machines.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleGermany and Italy arrest over 30 people in mafia food fraud sweep | News
Next Article North Carolina Senate Republicans choose Lee as the next majority leader
user
  • Website

Related Posts

Hackers use Tiktok videos to distribute Vidar and Stealc malware via Clickfix techniques

May 23, 2025

VisicorTrap uses Cisco flaws to build a global honeypot from 5,300 compromised devices

May 23, 2025

Discover the Importance of Fact-Checking: Empower Your Digital Self in the Age of Misinformation

May 23, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Beyond Hype: 55% of Spanish Companies Prove AI’s Impact on Decisions

Trump administration’s sanctions on Harvard international students hurt global appeal

Hackers use Tiktok videos to distribute Vidar and Stealc malware via Clickfix techniques

US judge blocks Trump’s efforts to ban Harvard University from registering foreign students | Education News

Trending Posts

US judge blocks Trump’s efforts to ban Harvard University from registering foreign students | Education News

May 23, 2025

Trump threatens 50% tariffs in the EU, 25% with Apple, ratchets trade war | Trade War News

May 23, 2025

Pakistan and Afghanistan move towards “recovery of tie” in talks with China | Taliban News

May 23, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Beyond Hype: 55% of Spanish Companies Prove AI’s Impact on Decisions

Prices hit $3,500 as Apple faces a 25% tariff threat on iPhones not made in the US

Venom Foundation achieves 150k TPS in closed network stress tests, paving the way for mainnet upgrades in 2025

Discover the Importance of Fact-Checking: Empower Your Digital Self in the Age of Misinformation

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.