Fun

Kubernetes Clusters Used to Mine Monero by Attackers

News Feed - 2021-07-26 06:07:41

Kubernetes Clusters Used to Mine Monero by Attackers


Attackers are abusing an attack vector present in one of the most popular execution engines (Argo Workflows) to repurpose Kubernetes systems to mine cryptocurrencies. The attack exploits a vulnerability in the system of permissions of Argo Workflows machines connected to the internet, deploying malicious workflows that install Monero-based containers. Attackers Leveraging Argo Workflows for Crypto Mining


A group of attackers discovered a new attack vector that uses a vulnerability in the permission system of Argo Workflows, one of the most used execution engines for Kubernetes, to install cryptocurrency mining modules in machines connected to the internet. This vulnerability means that every instance of Kubernetes, one of the most used cloud computing systems, could be used to mine Monero if it is paired with Argo Workflows.


A report from Intezer, a cybersecurity firm, informs they have already identified infected nodes and others vulnerable to this attack. The unprotected nodes allow any user to ping them and insert their own workflows into the system. This means anyone can use the resources in a vulnerable system and direct them to any task.


Luckily for attackers, there are several Monero-based cryptocurrency mining containers that can be leveraged easily to start mining Monero using these Kubernetes machines. Most of them are derived from kannix/monero-miner, but there are more than 45 other containers available to use. This is why security experts are anticipating large-scale attacks involving this vulnerability. Cloud Computing Vulnerability


This is just one of the recent attack vectors compromising cloud computing platforms and being used to enable cryptocurrency mining. Just last month, Microsoft informed of a similar attack that also targeted Kubernetes clusters with Kubeflow machine learning (ML) instances. Attackers use the vulnerable nodes to mine monero and also ethereum using Ethminer.


Attacks to this kind of platform started gaining traction back in April 2020, when Microsoft reported an instance that caused tens of thousands of infections in just two hours. These attacks have also prompted companies to switch their policies to avoid abuse. This is the case of Docker, which had to put limits to the free tier of its product because attackers were using its autobuild function to deploy cryptocurrency miners in its free servers.


What do you think about these attacks targeting Kubernetes nodes? Tell us in the comments section below. Thorchain Trolled by Hacker After Two Successful Seven-Figure Exploits NEWS | 1 hour ago Tesla Q2-2021 Earnings Call to Shed Light on Its Bitcoin Holdings NEWS | 17 hours ago Tags in this story argo workflows, attackers, Cloud Computing, cryptocurrency mining, docker, kubernetes, Monero


Image Credits: Shutterstock, Pixabay, Wiki Commons Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments

News Feed

Does the metaverse need to be on the blockchain? Execs weigh in
Ezra Reguerra11 hours agoDoes the metaverse need to be on the blockchain? Execs weigh inImaginary Ones co-founder Clement Chia believes that simply adding blockchain to the metaverse doesn’t solve its “purpose” pro
BTC price taps $58K as vital Bitcoin bull market trendline reemerges
William Suberg8 hours agoBTC price taps $58K as vital Bitcoin bull market trendline reemergesBitcoin shrugs off the latest round of German government onchain transactions, but BTC price resistance trendlines stay out of
Zhiyuan Sun8 hours agoHTX to restore services ‘within 24 hours’ after $13.6M hack”Huobi HTX has now properly handled this attack,” the crypto exchange stated.9919 Total views8 Total sharesListen to article 0:00Ne
Victory of President-Elect ‘Lula’ in Brazil Might Bring the Rise of a Common Currency for Latam
Victory of President-Elect "Lula" in Brazil Might Bring the Rise of a Common Currency for Latam The victory President-Elect Luis Inacio Lula Da Silva obtained on Oct. 30 over the i
AMC and Sony to Gift NFTs to ‘Spider-Man: No Way Home’ Advance Opening Ticket Buyers
AMC and Sony to Gift NFTs to "Spider-Man: No Way Home" Advance Opening Ticket Buyers The theatre chain AMC and Sony Pictures are offering NFT’s as a present for early buyers
Cryptography startup Fabric raises $33M for new data privacy chip
Ana Paula Pereira2 hours agoCryptography startup Fabric raises $33M for new data privacy chipBlockchain Capital and 1kx co-led the Series A round that will back the development of a new computing chip focused on data pri
Amaka Nwaokocha13 hours agoRipple CEO slams SEC over the use of XRP report in lawsuitBrad Garlinghouse stressed Ripple’s unchanged commitment to transparency but hinted that future reports might undergo some changes.10
Bakkt to Launch Crypto ‘Consumer App’ in First Half of 2020
Bakkt plans to launch a consumer-facing app to help retail customers transact with cryptocurrencies, the company announced Monday. In a blog post, Bakkt chief product officer Mike B
Professor Steve Hanke Says US Economy Was Flat Over the Last Year, but Stresses ‘It’s Going to Hit South’
Professor Steve Hanke Says US Economy Was Flat Over the Last Year, but Stresses ‘It’s Going to Hit South’ Amid the chaotic economy, plagued with central bank tinkering, suppl
Rakesh Upadhyay5 hours agoBitcoin price gathers strength as SOL, AVAX, FIL and EOS prep for a breakoutSOL, AVAX, FIL and EOS price are beginning to look attractive, especially if Bitcoin opens the week with a renewed att
Cross-Chain Bridge Nomad Loses $190 Million Making It 2022’s Third-Largest Crypto Heist
Cross-Chain Bridge Nomad Loses $190 Million Making It 2022"s Third-Largest Crypto Heist On Monday, the cross-chain token bridge Nomad was attacked and hackers managed to siphon $19
Binance Bans Russians From P2P Transactions With Dollars and Euros
Binance Bans Russians From P2P Transactions With Dollars and Euros Cryptocurrency exchange Binance has introduced new restrictions for Russian users, in accordance with the latest