Fun

Malware exploits weak passwords in PostgreSQL for cryptojacking

News Feed - 2024-08-22 06:08:23

Derek Andersen2 hours agoMalware exploits weak passwords in PostgreSQL for cryptojackingUp to 800,000 internet-connected databases could be vulnerable to crypto-mining malware that will use their computing capacity.359 Total views1 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTCOINTELEGRAPH IN YOUR SOCIAL FEEDFollow ourSubscribe onNew malware has been uncovered that targets databases to install cryptocurrency mining software. Dubbed PG_MEM, the malware could potentially hit any of the more than 800,000 PostgreSQL-managed databases if they have weak passwords.


According to cloud-native cybersecurity company Aqua, PG_MEM is installed after a brute force attack finds a weak password on a PostgreSQL-managed database. PostgreSQL is a popular object-relational database management system that is used by databases with internet connectivity. There are well over 800,000 such databases, with almost 300,000 located in the United States and over 100,000 in Poland.Malware sends spare compute to a mining pool


Once the threat actor has gained entry to a database, it creates a new user with login capability and high privileges. It downloads two files from the threat actor’s server and even manages to cover its tracks and block entry to other threat actors eager to exploit the database’s computing capacity. This could be happening often:“This campaign is exploiting internet facing Postgres databases with weak password. Many organizations connect their databases to the internet, weak password is a result of a misconfiguration, and lack of proper identity controls. This is not a rare issue and many large organizations suffer from these problems.”


The malware, once operational, connects to a mining pool and uses the host’s computing resources, combined with those of other miners, to increase the chances of mining a new block.PG_MEM attack flow. Source: Aqua Security


Related: Windows tool targeted by hackers deploys crypto-mining malwareA growing problem — or solution


The use of malware to mine cryptocurrency is known as cryptojacking. Cryptojacking malware can be installed on personal computers as well. It is becoming more frequent. Cointelegraph noted that crypto malware attacks rose by 400% year-on-year in the first half of 2023.Source: Aqua Security


Unused capacity can be harnessed by rightful hardware users for mining or other uses. Decentralized cloud infrastructure provider Aethir, for example, operates a GPU-as-a-service decentralized physical infrastructure network (DePIN) that sources compute from tier 3 and tier 4 data centers to provide inexpensive, scalable computing service to its clients.


Magazine: Weird ‘null address’ iVest hack, millions of PCs still vulnerable to ‘Sinkclose’ malware: Crypto-Sec# Bitcoin# Security# Hackers# CryptojackingAdd reaction

News Feed

Bitcoin Needs ‘Real Use Cases’ to Become Digital Gold, Says ICE Chief
Bitcoin might become “digital gold,” but first it needs to be used more in everyday business, Intercontinental Exchange’s chief executive said. During a quarterly
Animoca Brands Brings “MotoGP™ Ignition” to Flow Blockchain, Announces First Collectibles NFT Sale
Animoca Brands Brings “MotoGP™ Ignition” to Flow Blockchain, Announces First Collectibles NFT Sale press release PRESS RELEASE. 25 February 2021 –Anim
Tristan Greene6 hours agoLocal Web3 community launches ‘Crypto Aid Israel’ to help displaced citizensThe charity campaign aims to raise funds for humanitarian aid to help Israelis affected by the recent conflict.1957
Cypher core contributor admits to stealing $260K and gambling it away
Jesse Coghlan7 hours agoCypher core contributor admits to stealing $260K and gambling it awayThe contributor, “hoak,” said their actions were due to a “crippling gambling addiction” and “psychological factors t
Crypto VC Paradigm seeking up to $850M raise for fund: Report
Brayden Lindrea8 hours agoCrypto VC Paradigm seeking up to $850M raise for fund: ReportIf Paradigm completes the raise, it would be it’s largest since it raised a $2.5 billion fund at the peak of the last cycle’s bul
White House Releases ‘First-Ever’ Framework for Digital Asset Development — Crypto Industry Leader Says Recommendations Are Unclear
White House Releases "First-Ever" Framework for Digital Asset Development — Crypto Industry Leader Says Recommendations Are Unclear The White House has now released what it calle
Bitcoin Email Scams 2020: Threatening Blackmail Tactics Used to Demand BTC
Bitcoin Email Scams 2020: Threatening Blackmail Tactics Used to Demand BTC The number of bitcoin email scams has been growing in 2020 and the authorities in several countries have w
Safe token drops 42% after enabling transfers
Ezra Reguerra13 hours agoSafe token drops 42% after enabling transfersSafe’s decentralized autonomous organization enabled token transferability on April 23 after achieving several milestones.2430 Total views4 Total sh
Fund Manager Says Bitcoin Will Crush Gold, Hit $1 Million By 2029
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Report: Judge in MTI Liquidation Case Issues Order Designating Bitcoin an Intangible Asset
Report: Judge in MTI Liquidation Case Issues Order Designating Bitcoin an Intangible Asset A judge in the collapsed online bitcoin trading platform Mirror Trading International
Solana Holds Bullish Pattern – Expert Sets $140 Target
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Open-source Bitcoin education aims to spread global financial literacy
Savannah Fortis9 hours agoOpen-source Bitcoin education aims to spread global financial literacyMi Primer Bitcoin, a pioneering Bitcoin education initiative in El Salvador, released the latest edition of its program, emp