Fun

Malware exploits weak passwords in PostgreSQL for cryptojacking

News Feed - 2024-08-22 06:08:23

Derek Andersen2 hours agoMalware exploits weak passwords in PostgreSQL for cryptojackingUp to 800,000 internet-connected databases could be vulnerable to crypto-mining malware that will use their computing capacity.359 Total views1 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTCOINTELEGRAPH IN YOUR SOCIAL FEEDFollow ourSubscribe onNew malware has been uncovered that targets databases to install cryptocurrency mining software. Dubbed PG_MEM, the malware could potentially hit any of the more than 800,000 PostgreSQL-managed databases if they have weak passwords.


According to cloud-native cybersecurity company Aqua, PG_MEM is installed after a brute force attack finds a weak password on a PostgreSQL-managed database. PostgreSQL is a popular object-relational database management system that is used by databases with internet connectivity. There are well over 800,000 such databases, with almost 300,000 located in the United States and over 100,000 in Poland.Malware sends spare compute to a mining pool


Once the threat actor has gained entry to a database, it creates a new user with login capability and high privileges. It downloads two files from the threat actor’s server and even manages to cover its tracks and block entry to other threat actors eager to exploit the database’s computing capacity. This could be happening often:“This campaign is exploiting internet facing Postgres databases with weak password. Many organizations connect their databases to the internet, weak password is a result of a misconfiguration, and lack of proper identity controls. This is not a rare issue and many large organizations suffer from these problems.”


The malware, once operational, connects to a mining pool and uses the host’s computing resources, combined with those of other miners, to increase the chances of mining a new block.PG_MEM attack flow. Source: Aqua Security


Related: Windows tool targeted by hackers deploys crypto-mining malwareA growing problem — or solution


The use of malware to mine cryptocurrency is known as cryptojacking. Cryptojacking malware can be installed on personal computers as well. It is becoming more frequent. Cointelegraph noted that crypto malware attacks rose by 400% year-on-year in the first half of 2023.Source: Aqua Security


Unused capacity can be harnessed by rightful hardware users for mining or other uses. Decentralized cloud infrastructure provider Aethir, for example, operates a GPU-as-a-service decentralized physical infrastructure network (DePIN) that sources compute from tier 3 and tier 4 data centers to provide inexpensive, scalable computing service to its clients.


Magazine: Weird ‘null address’ iVest hack, millions of PCs still vulnerable to ‘Sinkclose’ malware: Crypto-Sec# Bitcoin# Security# Hackers# CryptojackingAdd reaction

News Feed

NASDAQ-Listed HIVE Blockchain to Expand Data Center in New Brunswick, Canada With 40 Megawatts Capacity
NASDAQ-Listed HIVE Blockchain to Expand Data Center in New Brunswick, Canada With 40 Megawatts Capacity sponsored HIVE Blockchain is set to expand its data center campus in New Brun
A Step-by-Step Guide on How to Access Your ETHW Tokens if You Held ETH Before The Merge
A Step-by-Step Guide on How to Access Your ETHW Tokens if You Held ETH Before The Merge With the new Ethereumpow (ETHW) network launch, ethereum holders are eligible to receive a s
CFTC commissioner wants to create AI fraud task force
Tristan Greene7 hours agoCFTC commissioner wants to create AI fraud task forceCommissioner Kristin Johnson’s remarks came just a day after the CFTC appointed its first chief AI officer.4097 Total views4 Total sharesLis
Darknet Giant Darkmarket Shut Down, Alleged Operator Arrested
Darknet Giant Darkmarket Shut Down, Alleged Operator Arrested The authorities in seven countries and Europol have jointly taken down Darkmarket, one of the large
Stimulus, QE, Rate Cuts: Coronavirus Fuels Central Banks’ Monetary Easing Policy
Stimulus, QE, Rate Cuts: Coronavirus Fuels Central Banks" Monetary Easing Policy The world has been focused on the coronavirus outbreak that’s claimed 105,612 cases and 3,5
Kraken Charged by CFTC Over Margined Crypto Transactions, $1.25 Million Penalty Imposed
Kraken Charged by CFTC Over Margined Crypto Transactions, $1.25 Million Penalty Imposed The Commodity Futures Trading Commission (CFTC) has charged Payward Ventures, the operator o
AMC Confirms Plan to Accept Bitcoin, Ethereum, Litecoin, and Bitcoin Cash
AMC Confirms Plan to Accept Bitcoin, Ethereum, Litecoin, and Bitcoin Cash The world’s largest movie exhibition company, AMC Entertainment, has announced its plan to accept c
Bitcoin transfer costs fall to 2020 lows
Arijit Sarkar47 minutes agoBitcoin transfer costs fall to 2020 lowsBitcoin transaction fees hit a four-year low on July 7, falling to $38.69. Miners remain profitable due to reduced network difficulty and lower computati
Tristan Greene5 hours agoHumans and AI often prefer sycophantic chatbot answers to the truth — StudyThe team at Anthropic AI found that five “state-of-the-art” language models exhibit sycophancy, indicating the pro
Claim Your First NFT Top-Level Domain for Web3 on Quik․com
Claim Your First NFT Top-Level Domain for Web3 on Quik․com sponsored NFT domainsenable users to establish a presence on the decentralized web and the metaverse, with Quik.com prov
Central Bank of Nigeria Orders Banks to Close Accounts of Crypto Clients
Central Bank of Nigeria Orders Banks to Close Accounts of Crypto Clients The Central Bank of Nigeria (CBN) has circulated a letter directing banks and financial
Altseason is coming — or at least data suggests that its close
Nancy Lubale6 hours agoAltseason is coming — or at least data suggests that its closeCrypto traders and several metrics suggest that an altcoin season is about to begin.2068 Total views8 Total sharesListen to article 0