Fun

Kubernetes Clusters Used to Mine Monero by Attackers

News Feed - 2021-07-26 06:07:41

Kubernetes Clusters Used to Mine Monero by Attackers


Attackers are abusing an attack vector present in one of the most popular execution engines (Argo Workflows) to repurpose Kubernetes systems to mine cryptocurrencies. The attack exploits a vulnerability in the system of permissions of Argo Workflows machines connected to the internet, deploying malicious workflows that install Monero-based containers. Attackers Leveraging Argo Workflows for Crypto Mining


A group of attackers discovered a new attack vector that uses a vulnerability in the permission system of Argo Workflows, one of the most used execution engines for Kubernetes, to install cryptocurrency mining modules in machines connected to the internet. This vulnerability means that every instance of Kubernetes, one of the most used cloud computing systems, could be used to mine Monero if it is paired with Argo Workflows.


A report from Intezer, a cybersecurity firm, informs they have already identified infected nodes and others vulnerable to this attack. The unprotected nodes allow any user to ping them and insert their own workflows into the system. This means anyone can use the resources in a vulnerable system and direct them to any task.


Luckily for attackers, there are several Monero-based cryptocurrency mining containers that can be leveraged easily to start mining Monero using these Kubernetes machines. Most of them are derived from kannix/monero-miner, but there are more than 45 other containers available to use. This is why security experts are anticipating large-scale attacks involving this vulnerability. Cloud Computing Vulnerability


This is just one of the recent attack vectors compromising cloud computing platforms and being used to enable cryptocurrency mining. Just last month, Microsoft informed of a similar attack that also targeted Kubernetes clusters with Kubeflow machine learning (ML) instances. Attackers use the vulnerable nodes to mine monero and also ethereum using Ethminer.


Attacks to this kind of platform started gaining traction back in April 2020, when Microsoft reported an instance that caused tens of thousands of infections in just two hours. These attacks have also prompted companies to switch their policies to avoid abuse. This is the case of Docker, which had to put limits to the free tier of its product because attackers were using its autobuild function to deploy cryptocurrency miners in its free servers.


What do you think about these attacks targeting Kubernetes nodes? Tell us in the comments section below. Thorchain Trolled by Hacker After Two Successful Seven-Figure Exploits NEWS | 1 hour ago Tesla Q2-2021 Earnings Call to Shed Light on Its Bitcoin Holdings NEWS | 17 hours ago Tags in this story argo workflows, attackers, Cloud Computing, cryptocurrency mining, docker, kubernetes, Monero


Image Credits: Shutterstock, Pixabay, Wiki Commons Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments

News Feed

Turner Wright11 hours agoSam Bankman-Fried’s lawyers push for temporary release, object to prosecutors’ proposed dealThe U.S. Justice Department has produced “millions of pages of documents” related to SBF’s cr
Growing Number of US Mayors Want to Be Paid in Bitcoin
Growing Number of US Mayors Want to Be Paid in Bitcoin A growing number of mayors in cities across the U.S. have said they want to be paid in bitcoin. The mayor of Miami said he is
Chinese Central Bank Official Calls for Commercial Bank Blockchain Adoption
The head of the technology department at the People’s Bank of China (PBoC) has called for commercial banks to adopt blockchain technology in digital finance. As reported by Reute
Bitcoin price entering ‘euphoria’ zone amid wealth rotation from ‘HODLers to new investors’ — Data
Nancy Lubale2 hours agoBitcoin price entering ‘euphoria’ zone amid wealth rotation from ‘HODLers to new investors’ — DataAccording to Glassnode, BTC market sentiment is approaching the “euphoria” stage amid
Prashant Jha10 hours agoFTX’s $3.4B crypto liquidation: What it means for crypto marketsBankrupt crypto exchange FTX has been approved to liquidate nearly $3.4 billion worth of crypto assets, creating a sense of panic
Augmented Reality Firm Nextech AR Joins the Bitcoin Treasuries Bandwagon, Buys $2 Million BTC
Augmented Reality Firm Nextech AR Joins the Bitcoin Treasuries Bandwagon, Buys $2 Million BTC On the heels of the Canadian company Mogo purchasing bitcoin for tr
Brayden Lindrea8 hours ago‘NFTs will win on Bitcoin’ — OnChainMonkey NFT collection ditches EthereumMetagood CEO Danny Yang attributed the move to the Bitcoin network being seen as a more secure platform for its us
Rakesh Upadhyay5 hours agoPrice analysis 7/7: BTC, ETH, BNB, XRP, ADA, DOGE, SOL, LTC, MATIC, DOTBitcoin and select altcoins are finding buyers at lower levels, indicating a pick-up in positive sentiment.2105 Total views
YFX.Com – DEX That Offers 100x Trading Leverage on Perpetual Contracts
YFX.Com - DEX That Offers 100x Trading Leverage on Perpetual Contracts PRESS RELEASE. YFX, the first DEX that offers 100x trading leverage on perpetual contracts
Pundits worry SEC’s Ethereum probe could be used to hold back ETFs
Brayden Lindrea3 hours agoPundits worry SEC’s Ethereum probe could be used to hold back ETFsThe SEC’s reported investigation into the Ethereum Foundation could explain why the regulator hasn’t been forthcoming with
Donald Trump raked in over $7M from NFTs, new disclosure shows
Tom Mitchelhill3 hours agoDonald Trump raked in over $7M from NFTs, new disclosure showsFormer president Donald Trump disclosed that he owns up to $5 million in crypto and has earned over $7 million from his three NFT co
Biggest Movers: GRT, LINK Rally to Multi-Week Highs on Friday
Biggest Movers: GRT, LINK Rally to Multi-Week Highs on Friday The graph was a notable mover in Friday’s session, as the token rallied to a multi-week high. Prices rose by as