Fun

Malware exploits weak passwords in PostgreSQL for cryptojacking

News Feed - 2024-08-22 06:08:23

Derek Andersen2 hours agoMalware exploits weak passwords in PostgreSQL for cryptojackingUp to 800,000 internet-connected databases could be vulnerable to crypto-mining malware that will use their computing capacity.359 Total views1 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTCOINTELEGRAPH IN YOUR SOCIAL FEEDFollow ourSubscribe onNew malware has been uncovered that targets databases to install cryptocurrency mining software. Dubbed PG_MEM, the malware could potentially hit any of the more than 800,000 PostgreSQL-managed databases if they have weak passwords.


According to cloud-native cybersecurity company Aqua, PG_MEM is installed after a brute force attack finds a weak password on a PostgreSQL-managed database. PostgreSQL is a popular object-relational database management system that is used by databases with internet connectivity. There are well over 800,000 such databases, with almost 300,000 located in the United States and over 100,000 in Poland.Malware sends spare compute to a mining pool


Once the threat actor has gained entry to a database, it creates a new user with login capability and high privileges. It downloads two files from the threat actor’s server and even manages to cover its tracks and block entry to other threat actors eager to exploit the database’s computing capacity. This could be happening often:“This campaign is exploiting internet facing Postgres databases with weak password. Many organizations connect their databases to the internet, weak password is a result of a misconfiguration, and lack of proper identity controls. This is not a rare issue and many large organizations suffer from these problems.”


The malware, once operational, connects to a mining pool and uses the host’s computing resources, combined with those of other miners, to increase the chances of mining a new block.PG_MEM attack flow. Source: Aqua Security


Related: Windows tool targeted by hackers deploys crypto-mining malwareA growing problem — or solution


The use of malware to mine cryptocurrency is known as cryptojacking. Cryptojacking malware can be installed on personal computers as well. It is becoming more frequent. Cointelegraph noted that crypto malware attacks rose by 400% year-on-year in the first half of 2023.Source: Aqua Security


Unused capacity can be harnessed by rightful hardware users for mining or other uses. Decentralized cloud infrastructure provider Aethir, for example, operates a GPU-as-a-service decentralized physical infrastructure network (DePIN) that sources compute from tier 3 and tier 4 data centers to provide inexpensive, scalable computing service to its clients.


Magazine: Weird ‘null address’ iVest hack, millions of PCs still vulnerable to ‘Sinkclose’ malware: Crypto-Sec# Bitcoin# Security# Hackers# CryptojackingAdd reaction

News Feed

Japan and Philippines Discuss Pro-Crypto Laws, Cooperation Among Asian Countries
Japan and Philippines Discuss Pro-Crypto Laws, Cooperation Among Asian Countries Japanese Minister Naokazu Takemoto and Philippine Cabinet member Raul Lambino of Crypto Valley of
Brazilian Companies Break Crypto Purchasing Records Again in October
Brazilian Companies Break Crypto Purchasing Records Again in October According to the latest reports from the Brazilian tax authority (RFB), institutions have again broken crypto p
Skybridge Capital Cofounder Says Gamestop Activity Is ‘More Proof That Bitcoin Will Work’
Skybridge Capital Cofounder Says Gamestop Activity Is "More Proof That Bitcoin Will Work" The New York-based Skybridge Capital cofounder, Anthony Scaramucci, rec
Panther Completes the Decentralized Launch of Its Protocol’s v0․5, a DAO-Led Effort
Panther Completes the Decentralized Launch of Its Protocol’s v0․5, a DAO-Led Effort press release PRESS RELEASE.Panther, a cross-chain application that will allow retail users a
Xbox Boss Phil Spencer Addresses Rise of NFT Gaming; Feels Some of It Is “Exploitive”
Xbox Boss Phil Spencer Addresses Rise of NFT Gaming; Feels Some of It Is "Exploitive" Phil Spencer, executive vice president of gaming at Microsoft and the individual responsible f
KICK.IO’s Token Will Be Available on ExMarkets LaunchPad, 15th September
KICK.IO"s Token Will Be Available on ExMarkets LaunchPad, 15th September sponsored As the $ADAbull market continues to gather steam – with new price records set each month&#x
Report: Pakistan Likely to Earn Billions From Cryptocurrency
Report: Pakistan Likely to Earn Billions From Cryptocurrency According to a document produced by a Pakistani policy advisory board, the country is likely to earn billions of dollar
Building a Decentralized and Uncensorable Internet — The Nexus Protocol
Building a Decentralized and Uncensorable Internet — The Nexus Protocol PRESS RELEASE. On December 21st, 2020, the Nexus Protocol white paperwas released. The
Bitcoin fees crash after record daily average of $128 on halving day
Brayden Lindrea7 hours agoBitcoin fees crash after record daily average of $128 on halving dayThe surge in block fees on the halving day was more than making up for the halved block subsidy miners were hit with — but t
Tether mints 1.3B USDT since market bottom — Can it push Bitcoin above $65K?
Zoltan Vardai11 hours agoTether mints 1.3B USDT since market bottom — Can it push Bitcoin above $65K?The newly minted stablecoins could help push Bitcoin’s price above the $65,000 resistance, which is the short-term
US Seizes Cryptocurrency Worth $30 Million From North Korean Hackers
US Seizes Cryptocurrency Worth $30 Million From North Korean Hackers Blockchain data analytics firm Chainalysis has revealed that U.S. authorities have seized cryptocurrency worth
Morgan Stanley discloses $188M in BlackRock Bitcoin ETF holdings
Turner Wright2 hours agoMorgan Stanley discloses $188M in BlackRock Bitcoin ETF holdingsThe investment firm disclosed to the SEC that it held more than 5.5 million shares of the iShares Bitcoin Trust in the second quarte