Fun

Malware exploits weak passwords in PostgreSQL for cryptojacking

News Feed - 2024-08-22 06:08:23

Derek Andersen2 hours agoMalware exploits weak passwords in PostgreSQL for cryptojackingUp to 800,000 internet-connected databases could be vulnerable to crypto-mining malware that will use their computing capacity.359 Total views1 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTCOINTELEGRAPH IN YOUR SOCIAL FEEDFollow ourSubscribe onNew malware has been uncovered that targets databases to install cryptocurrency mining software. Dubbed PG_MEM, the malware could potentially hit any of the more than 800,000 PostgreSQL-managed databases if they have weak passwords.


According to cloud-native cybersecurity company Aqua, PG_MEM is installed after a brute force attack finds a weak password on a PostgreSQL-managed database. PostgreSQL is a popular object-relational database management system that is used by databases with internet connectivity. There are well over 800,000 such databases, with almost 300,000 located in the United States and over 100,000 in Poland.Malware sends spare compute to a mining pool


Once the threat actor has gained entry to a database, it creates a new user with login capability and high privileges. It downloads two files from the threat actor’s server and even manages to cover its tracks and block entry to other threat actors eager to exploit the database’s computing capacity. This could be happening often:“This campaign is exploiting internet facing Postgres databases with weak password. Many organizations connect their databases to the internet, weak password is a result of a misconfiguration, and lack of proper identity controls. This is not a rare issue and many large organizations suffer from these problems.”


The malware, once operational, connects to a mining pool and uses the host’s computing resources, combined with those of other miners, to increase the chances of mining a new block.PG_MEM attack flow. Source: Aqua Security


Related: Windows tool targeted by hackers deploys crypto-mining malwareA growing problem — or solution


The use of malware to mine cryptocurrency is known as cryptojacking. Cryptojacking malware can be installed on personal computers as well. It is becoming more frequent. Cointelegraph noted that crypto malware attacks rose by 400% year-on-year in the first half of 2023.Source: Aqua Security


Unused capacity can be harnessed by rightful hardware users for mining or other uses. Decentralized cloud infrastructure provider Aethir, for example, operates a GPU-as-a-service decentralized physical infrastructure network (DePIN) that sources compute from tier 3 and tier 4 data centers to provide inexpensive, scalable computing service to its clients.


Magazine: Weird ‘null address’ iVest hack, millions of PCs still vulnerable to ‘Sinkclose’ malware: Crypto-Sec# Bitcoin# Security# Hackers# CryptojackingAdd reaction

News Feed

South Korean government to launch crypto transaction monitoring system
Turner Wright7 hours agoSouth Korean government to launch crypto transaction monitoring systemCrypto exchanges subject to a new South Korean law have implemented a system allowing authorities to receive reports on suspic
A ‘simple’ hard fork could subvert a quantum attack on Ethereum: Vitalik Buterin
Tom Mitchelhill6 hours agoA ‘simple’ hard fork could subvert a quantum attack on Ethereum: Vitalik ButerinThe technology required to make Ethereum immune from a quantum attack could be developed starting “tomorrow,
China Saw $11.4 Billion in Crypto-Based Capital Flight Last Year
China Saw $11.4 Billion in Crypto-Based Capital Flight Last Year On January 8, China-based blockchain security firm Peckshield published its “2019 Global Digital Asset AML
VIC Rewards and XcelTrip Are Set To Redefine Global Wellness and Vitality Marketspace
VIC Rewards and XcelTrip Are Set To Redefine Global Wellness and Vitality Marketspace PRESS RELEASE. Dr. Richard Satur, CEO of VIC Rewards, and Gyanendra Khadka,
Brayden Lindrea3 hours agoCoinbase disputes SEC’s crypto authority in final bid to toss regulator’s suitCoinbase says the SEC’s definition of an investment contract isn’t in line with U.S. securities laws.2053 To
Ezra Reguerra14 hours agoCrypto Thanksgiving: Community hails industry milestones, expresses gratitudeA community member compared crypto to a turkey that takes time to cook and expressed gratitude for the opportunity to
Mac users beware: AMOS malware clones wallet apps and comes for your crypto
Christopher Roark10 hours agoMac users beware: AMOS malware clones wallet apps and comes for your cryptoThe AMOS stealer targeting Mac users can now clone Ledger Live software and may soon clone other wallet apps, warns
Bitcoin halving supply shock set to shake up mining sector
Daniel Ramirez-Escudero7 hours agoBitcoin halving supply shock set to shake up mining sectorThe halving could impact the number of daily available BTC by reducing the miner rewards by 50%.1823 Total views24 Total sharesL
Marvin Bertin11 hours agoCentralized vs. decentralized orders matching on DEXsCentralized and decentralized order batchers are central to this discussion, each representing a different approach to order matching.466 Tota
Venezuela Seizes 315 Bitcoin Mining Rigs: Miners Discuss Illegal Confiscation, Police Extortion
Venezuela Seizes 315 Bitcoin Mining Rigs: Miners Discuss Illegal Confiscation, Police ExtortionThe Venezuelan military has seized 315 Bitmain Antminer S9 bitcoin mining rigs it clai
New York Mayor Supportive of Mining Restrictions but Maintains Crypto Hub Objective
New York Mayor Supportive of Mining Restrictions but Maintains Crypto Hub Objective Mayor of New York City Eric Adams took a supportive, if somewhat veiled, stance on the partial c
William Suberg14 hours agoBTC price tracks $26.5K as Bitcoin speculator supply hits 12-year lowBTC price action stays firmly within an established range, while analysis shows that overall Bitcoin investor composition is