Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,151,602 members, 7,812,972 topics. Date: Tuesday, 30 April 2024 at 12:36 AM

Keep An Eye Out! Dockers, AWS, And Alibaba Cloud Are Being Targeted By Cryptocur - Computers - Nairaland

Nairaland Forum / Science/Technology / Computers / Keep An Eye Out! Dockers, AWS, And Alibaba Cloud Are Being Targeted By Cryptocur (348 Views)

Unveiling Alibaba’s Strategic Turnaround Plan In 2024 / Alibaba/aliexpress Checkout Available NO LIMIT / Who Can Add Members From A Targeted Telegram Group To Another Telegram Channel. (2) (3) (4)

(1) (Reply)

Keep An Eye Out! Dockers, AWS, And Alibaba Cloud Are Being Targeted By Cryptocur by Maguire004: 1:33pm On May 07, 2022
As part of an ongoing malware effort, LemonDuck, a cross-platform cryptocurrency mining botnet, is targeting Docker to mine cryptocurrency on Linux servers.

In a new study, CrowdStrike stated, “It operates an anonymous mining operation by using proxy pools, which disguise the wallet addresses.” “It avoids detection by targeting and disabling Alibaba Cloud’s monitoring service.”

LemonDuck is a malware that targets both Windows and Linux systems and is designed to mine Monero by exploiting system resources. However, it is also capable of credential theft, lateral movement, and the deployment of additional payloads for follow-on operations.

“It uses a wide range of spreading mechanisms — phishing emails, exploits, USB devices, and brute force, among others — and it has demonstrated that it can quickly take advantage of news, events, or the release of new exploits to run effective campaigns,” Microsoft wrote in a technical write-up of the malware last July.

LemonDuck-based attack chains exploited recently patched Exchange Server vulnerabilities in early 2021 to obtain access to obsolete Windows workstations and download backdoors and information stealers, including Ramnit.

CrowdStrike has discovered a new campaign that uses accessible Docker APIs as an initial access vector to run a rogue container to retrieve a Bash shell script file disguised as an innocuous PNG image file from a remote server.

According to the cybersecurity firm, similar image file droppers stored on LemonDuck-associated domains have been used by the threat actor since at least January 2021, according to historical data.

docker

The shell script that downloads the actual payload, terminates competing processes, disables Alibaba Cloud’s monitoring services, and finally downloads and starts the XMRig coin miner, is crucial to starting the attack.

The findings highlight the need of securing containers from possible dangers throughout the software supply chain, since hacked cloud instances have become a hub for illicit bitcoin mining activities.



TeamTNT targets AWS, Alibaba Cloud
The news comes after Cisco Talos revealed the toolset of a cybercrime outfit known as TeamTNT, which has a history of cryptojacking and backdooring cloud infrastructure.

code

“Cybercriminals who have been exposed by security researchers must update their tools in order to continue to operate successfully,” stated Darin Smith of Talos.

“TeamTNT’s tools show that cybercriminals are becoming more comfortable attacking modern settings like Docker, Kubernetes, and public cloud providers, which have previously been shunned by other cybercriminals who have focused on on-premise or mobile environments.”

Spring4Shell exploited for cryptocurrency mining
That’s not all, though. The serious remote code execution problem in Spring Framework (CVE-2022-22965) has been weaponized to deploy cryptocurrency miners, in yet another example of how threat actors quickly co-opt recently revealed flaws into their attacks.

To deploy the cryptocurrency miners, the exploitation efforts employ a bespoke web shell, but not before turning off the firewall and terminating other virtual currency miner processes.

“These cryptocurrency miners have the potential to affect a large number of users,” said Trend Micro researchers Nitesh Surana and Ashish Verma. “Especially since Spring is the most widely used framework for developing enterprise-level applications in Java, these cryptocurrency miners have the potential to affect a large number of users.”

Source : https://slytech.org/2022/04/22/keep-an-eye-out-dockers-aws-and-alibaba-cloud-are-being-targeted-by-cryptocurrency-miners/

Re: Keep An Eye Out! Dockers, AWS, And Alibaba Cloud Are Being Targeted By Cryptocur by Maguire004: 1:38pm On May 07, 2022
J
Re: Keep An Eye Out! Dockers, AWS, And Alibaba Cloud Are Being Targeted By Cryptocur by LossBenson(m): 7:31pm On May 23, 2022
Cloud computing offers businesses significant operational efficiencies over traditional servers. However, innovation and dependence on the cloud also creates new risks. Security issues are one of the risks. http://www.castadivaforums.io/ Therefore, cloud security assessment tools should not be neglected.

(1) (Reply)

Direct USA Used Apple Macbook Pro, Intel Core2, 120gb HDD 2gb RAM, 13.5inch / Corei5 500gb HDD 8gb Ram For 115k, Comes With A Laptop Bag / Amlogic S905X5 Processor With More Power On 6nm And H.266

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 11
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.