Fun

Kubernetes Clusters Used to Mine Monero by Attackers

News Feed - 2021-07-26 06:07:41

Kubernetes Clusters Used to Mine Monero by Attackers


Attackers are abusing an attack vector present in one of the most popular execution engines (Argo Workflows) to repurpose Kubernetes systems to mine cryptocurrencies. The attack exploits a vulnerability in the system of permissions of Argo Workflows machines connected to the internet, deploying malicious workflows that install Monero-based containers. Attackers Leveraging Argo Workflows for Crypto Mining


A group of attackers discovered a new attack vector that uses a vulnerability in the permission system of Argo Workflows, one of the most used execution engines for Kubernetes, to install cryptocurrency mining modules in machines connected to the internet. This vulnerability means that every instance of Kubernetes, one of the most used cloud computing systems, could be used to mine Monero if it is paired with Argo Workflows.


A report from Intezer, a cybersecurity firm, informs they have already identified infected nodes and others vulnerable to this attack. The unprotected nodes allow any user to ping them and insert their own workflows into the system. This means anyone can use the resources in a vulnerable system and direct them to any task.


Luckily for attackers, there are several Monero-based cryptocurrency mining containers that can be leveraged easily to start mining Monero using these Kubernetes machines. Most of them are derived from kannix/monero-miner, but there are more than 45 other containers available to use. This is why security experts are anticipating large-scale attacks involving this vulnerability. Cloud Computing Vulnerability


This is just one of the recent attack vectors compromising cloud computing platforms and being used to enable cryptocurrency mining. Just last month, Microsoft informed of a similar attack that also targeted Kubernetes clusters with Kubeflow machine learning (ML) instances. Attackers use the vulnerable nodes to mine monero and also ethereum using Ethminer.


Attacks to this kind of platform started gaining traction back in April 2020, when Microsoft reported an instance that caused tens of thousands of infections in just two hours. These attacks have also prompted companies to switch their policies to avoid abuse. This is the case of Docker, which had to put limits to the free tier of its product because attackers were using its autobuild function to deploy cryptocurrency miners in its free servers.


What do you think about these attacks targeting Kubernetes nodes? Tell us in the comments section below. Thorchain Trolled by Hacker After Two Successful Seven-Figure Exploits NEWS | 1 hour ago Tesla Q2-2021 Earnings Call to Shed Light on Its Bitcoin Holdings NEWS | 17 hours ago Tags in this story argo workflows, attackers, Cloud Computing, cryptocurrency mining, docker, kubernetes, Monero


Image Credits: Shutterstock, Pixabay, Wiki Commons Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments

News Feed

Ternoa (CAPS), Transmit Your Memories and Private Data Thanks to the Blockchain
Ternoa (CAPS), Transmit Your Memories and Private Data Thanks to the Blockchain sponsored How can you make sure that your memories and private data are transmitte
Wells Fargo: Cryptocurrency Has Entered ‘Hyper-Adoption Phase’
Wells Fargo: Cryptocurrency Has Entered "Hyper-Adoption Phase" Financial services firm Wells Fargo says that cryptocurrencies are viable investments that have entered the “h
Algorand Wins Sharia Compliance Certificate to Enter $70 Billion Market
Algorand has been certified as sharia-compliant, the company said Monday. The certification was provided by Bahrain-based Shariya Review Bureau (SRB) and indicates that the Algorand
Europe’s Securities Regulator ESMA Seeks to Obtain Crypto Transaction Data
Europe’s Securities Regulator ESMA Seeks to Obtain Crypto Transaction Data The European Securities and Markets Authority (ESMA) is gearing up to implement stricter oversight in r
100-Year-Old Pennsylvania-Based Bank Approved to Leverage Makerdao’s Stablecoin Vault
100-Year-Old Pennsylvania-Based Bank Approved to Leverage Makerdao"s Stablecoin Vault Makerdao, the decentralized autonomous organization (DAO) that issues the stablecoin DAI, appr
David Attlee11 hours agoWyoming stablecoin: Are state digital currencies even possible?The Stable Token Commission continues researching the potential implementation of stable tokens in Wyoming.647 Total views28 Total sh
BitMEX Says Quality Check ‘Failure’ Led to Email Privacy Breach
BitMEX says its internal processes “failed” last week, subsequently exposing thousands of the exchange’s clients to privacy risks. In a company blog posting on Mon
Is Defi Coming to Bitcoin Cash? An Overview of Detoken and the Anyhedge Protocol
Is Defi Coming to Bitcoin Cash? An Overview of Detoken and the Anyhedge Protocol Maybe you’ve heard of Anyhedge. Last April, news.Bitcoin.com published an
Tether discredits Ripple CEO comments over US scrutiny
Prashant Jha14 hours agoTether discredits Ripple CEO comments over US scrutinyTether has highlighted its compliance efforts after Ripple’s CEO said the U.S. government has its sights set on USDT.1960 Total views5 Total
South Korea to Start Taxing Bitcoin Profits in 2021
South Korea to Start Taxing Bitcoin Profits in 2021South Korea will start taxing profits from bitcoin (BTC) and other cryptocurrencies next year, according to local media reports.
How long will Bitcoin’s price consolidation last?
Zoltan Vardai6 hours agoHow long will Bitcoin’s price consolidation last?Some crypto analysts expect Bitcoin’s price consolidation to end based on technical chart patterns and falling exchange reserves.2247 Total vie
Coinbase Shutting Down Most Crypto Services in Japan After Series of Job Cuts Globally
Coinbase Shutting Down Most Crypto Services in Japan After Series of Job Cuts Globally The Nasdaq-listed cryptocurrency exchange Coinbase is closing down most of its operations in