Fun

Malware exploits weak passwords in PostgreSQL for cryptojacking

News Feed - 2024-08-22 06:08:23

Derek Andersen2 hours agoMalware exploits weak passwords in PostgreSQL for cryptojackingUp to 800,000 internet-connected databases could be vulnerable to crypto-mining malware that will use their computing capacity.359 Total views1 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTCOINTELEGRAPH IN YOUR SOCIAL FEEDFollow ourSubscribe onNew malware has been uncovered that targets databases to install cryptocurrency mining software. Dubbed PG_MEM, the malware could potentially hit any of the more than 800,000 PostgreSQL-managed databases if they have weak passwords.


According to cloud-native cybersecurity company Aqua, PG_MEM is installed after a brute force attack finds a weak password on a PostgreSQL-managed database. PostgreSQL is a popular object-relational database management system that is used by databases with internet connectivity. There are well over 800,000 such databases, with almost 300,000 located in the United States and over 100,000 in Poland.Malware sends spare compute to a mining pool


Once the threat actor has gained entry to a database, it creates a new user with login capability and high privileges. It downloads two files from the threat actor’s server and even manages to cover its tracks and block entry to other threat actors eager to exploit the database’s computing capacity. This could be happening often:“This campaign is exploiting internet facing Postgres databases with weak password. Many organizations connect their databases to the internet, weak password is a result of a misconfiguration, and lack of proper identity controls. This is not a rare issue and many large organizations suffer from these problems.”


The malware, once operational, connects to a mining pool and uses the host’s computing resources, combined with those of other miners, to increase the chances of mining a new block.PG_MEM attack flow. Source: Aqua Security


Related: Windows tool targeted by hackers deploys crypto-mining malwareA growing problem — or solution


The use of malware to mine cryptocurrency is known as cryptojacking. Cryptojacking malware can be installed on personal computers as well. It is becoming more frequent. Cointelegraph noted that crypto malware attacks rose by 400% year-on-year in the first half of 2023.Source: Aqua Security


Unused capacity can be harnessed by rightful hardware users for mining or other uses. Decentralized cloud infrastructure provider Aethir, for example, operates a GPU-as-a-service decentralized physical infrastructure network (DePIN) that sources compute from tier 3 and tier 4 data centers to provide inexpensive, scalable computing service to its clients.


Magazine: Weird ‘null address’ iVest hack, millions of PCs still vulnerable to ‘Sinkclose’ malware: Crypto-Sec# Bitcoin# Security# Hackers# CryptojackingAdd reaction

News Feed

Terra Protocol Reaches Maximum Issuance of UST Daily, LFG Foundation Steps In
Terra Protocol Reaches Maximum Issuance of UST Daily, LFG Foundation Steps In Terra, one of the top 10 cryptocurrency projects by market cap, has reached a UST-related milestone re
Central Bank of Nigeria Governor Defends Decision to Exclude Crypto Players, Says the Order Is ‘in the Best Interests of Nigerians’
Central Bank of Nigeria Governor Defends Decision to Exclude Crypto Players, Says the Order Is "in the Best Interests of Nigerians" The governor of the Central B
Guest Author4 hours ago3 reasons why Ethereum price is down against BitcoinETH price continues to lose ground against Bitcoin. Cointelegraph takes a closer look at the factors behind the weakening ETH/BTC pair.1625 Total
Bitcoin, Ethereum Technical Analysis: ETH Falls Below $1,300 Following Monday’s False Breakout
Bitcoin, Ethereum Technical Analysis: ETH Falls Below $1,300 Following Monday’s False Breakout Ethereum was in the red on Tuesday, as bears reentered the market following a faile
Vinnik to Be ‘Hostage’ in US Amid Russia’s War in Ukraine, Greek Lawyer Says
Vinnik to Be ‘Hostage’ in US Amid Russia’s War in Ukraine, Greek Lawyer Says If extradited to the United States, crypto exchange BTC-e’s alleged operator Alexander Vin
Nigeria rejects claims of Binance exec's poor health in custody
Amaka Nwaokocha1 hour agoNigeria rejects claims of Binance exec"s poor health in custodyMohammed Idris, Nigeria’s Minister of Information and National Orientation emphasized that Gambaryan enjoys full consular support
Elon Musk Relaunches Tesla Solar: 'Like a Money Printer on Your Roof'
TwitterFacebookLinkedInSource: Mark RALSTON / AFP (i), Shutterstock (ii). Image Edited by CCN.By CCN Markets: Elon Musk relaunched Tesla"s residential solar-power service and claime
NFT Sales Jumped 22% Higher This Month With $568 Million in NFTs Sold Across 20 Blockchains
NFT Sales Jumped 22% Higher This Month With $568 Million in NFTs Sold Across 20 Blockchains Non-fungible token (NFT) sales have shown improvement during the last month as 30-day st
Brazil and China Deepen Trade Integration to Move Away From US Dollar, as First Yuan-Based Settlement Is Processed
Brazil and China Deepen Trade Integration to Move Away From US Dollar, as First Yuan-Based Settlement Is Processed Brazil and China have reached a milestone in their economic integ
Oil Producers and Bitcoin Miners Meet in Texas to Discuss Cooperative Mining Possibilities
Oil Producers and Bitcoin Miners Meet in Texas to Discuss Cooperative Mining Possibilities A meetup in a vehicle warehouse in Houston served as an encounter point for oil producers
Brayden Lindrea4 hours ago‘Magnificent seven’ tech stocks tumble a whopping $280B as crypto surgesGoogle’s parent company, Alphabet, was the worst performer on the day, falling 9.5% in a massive $180-billion wipeou
Bitcoin Evangelist Andreas Antonopoulos Plans to Testify in Billion-Dollar Bitcoin Lawsuit
Bitcoin Evangelist Andreas Antonopoulos Plans to Testify in Billion-Dollar Bitcoin Lawsuit On Monday evening November 16, the popular bitcoin evangelist Andreas