• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Friday, September 12, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

Someone is roping Apache NiFi servers into a cryptomining botnet

31 May 2023
in Mining
Reading Time: 2 mins read
A A
0
Someone is roping Apache NiFi servers into a cryptomining botnet
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

Related articles

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024

If you’re running an Apache NiFi instance exposed on the internet and you have not secured access to it, the underlying host may already be covertly cryptomining on someone else’s behalf.

The attack

Indicators of the ongoing campaign were first spotted by the SANS Internet Storm Center when, on May 19th, their distributed sensor network detected a significant spike in requests for “/nifi.”

After redirecting some of the requests to their honeypot system running the latest version (v1.21.0) of the data processing and distribution solution, they discovered that someone is:

  • Accessing unsecured installations
  • Adding scheduled processors to retrieve and install scripts that install a cryptocurrency miner (Kinsing) and, in some cases, attempt to find other connected targets by searching the server for SSH credentials

Both scripts are kept in memory (i.e., they are not saved to the file system).

The first one attempts to do things like disable the firewall and monitoring tools, find and terminate other cryptomining tools, install the Kinsing cryptominer, make standard temporary directories immutable (likely to prevent additional exploits), and more.

The second one tries to determine the victim’s external IP address, collects SSH keys from the system, and tries to connect to other hosts and deploy the script delivering the cryptominer.

“The requests arrived almost exclusively from 109.207.200.43. In addition to scanning for NiFi, the same IP also sends requests for /boaform/admin/formLogin. Various routers use this URL as a login page and are often scanned for weak passwords and other vulnerabilities,” said Dr. Johannes Ullrich, Dean of Research at the SANS Technology Institute.

He told Help Net Security that based on the lateral movement they say, he thinks the attacker is likely using the routers as a stepping stone.

“Routers make bad cryptomining servers. Cryptomining may be what they end up doing if the lateral movement doesn’t get them anywhere (like our honeypot was on an isolated network with nowhere to go to).”

How many unsecured Apache NiFi instances are there?

Dr. Ullrich says he found around 100, but there are likely more. Many of the discovered unsecured instances are hosted with could providers (e.g., Azure).

“Due to its use as a data processing platform, NiFi servers often have access to business-critical data. NiFi presents an attractive target for anyone who wants to steal, modify or delete the data,” he says.

But they are also configured with larger CPUs to support data transformation tasks, meaning that they can also easily support cryptomining activities.

SANS ISC has provided the malicious scripts and indicators that point to compromise: malicious cron jobs for persistence, odd processors in the NiFi configuration, IP addresses, and hashes of the scripts and the cryptominer.

In general, though, Apache NiFi instances should not be internet-facing and access to them should be properly secured (as advised and instructed in the official sysadmin’s guide).

Source link

Cryptohopper
ADVERTISEMENT
[crypto-donation-box]
Tags: ApacheBotnetCryptoMiningNiFiropingServers
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Solana, Avalanche, And Caged Beasts – Exploring The Best Cryptocurrencies To Buy In 2023

Next Post

Solana leads way as large cryptocurrencies decrease

Related Posts

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
0

A fake news story circulated today about Russia’s supposed embrace of bitcoin mining and crypto payments. According to excited social...

New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
0

A new report estimates a $20 billion revenue opportunity in Bitcoin BTC/USD mining chips and hardware over the next five...

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

30 July 2024
0

(Bloomberg) -- Russia is moving to regulate the use of cryptocurrencies, as companies wrestle with increasing difficulties in foreign payments...

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

30 July 2024
0

The Russian central bank plans to initiate international payments in cryptocurrencies by the end of the year to overcome delays...

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

30 July 2024
0

Listed both on Wall Street and the London Stock Exchange (LSE) Bitcoin miner Argo Blockchain, has announced a £6.5 million...

Load More
Next Post
Solana leads way as large cryptocurrencies decrease

Solana leads way as large cryptocurrencies decrease

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
Dennis Potter Defends Bitcoin’s Low Fees Amid Security Concerns

Dennis Potter Defends Bitcoin’s Low Fees Amid Security Concerns

12 September 2025
Galaxy Digital Buys 2.31 Million Solana Tokens Worth Nearly 6 Million – Yahoo Finance

Galaxy Digital Buys 2.31 Million Solana Tokens Worth Nearly $536 Million – Yahoo Finance

12 September 2025
4 Key Signs Altcoin Season Is Accelerating Fast in September 2025

4 Key Signs Altcoin Season Is Accelerating Fast in September 2025

12 September 2025
BitMine’s Ethereum Holdings Top 2.1 Million After Fresh 46,255 ETH Buy

BitMine’s Ethereum Holdings Top 2.1 Million After Fresh 46,255 ETH Buy

12 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • Dennis Potter Defends Bitcoin’s Low Fees Amid Security Concerns
  • Galaxy Digital Buys 2.31 Million Solana Tokens Worth Nearly $536 Million – Yahoo Finance
  • 4 Key Signs Altcoin Season Is Accelerating Fast in September 2025
  • BitMine’s Ethereum Holdings Top 2.1 Million After Fresh 46,255 ETH Buy
  • FTX, Alameda Redeem $45 Million in Solana From Staking – Cryptonews

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 115,141.00
  • ethereumEthereum (ETH) $ 4,524.02
  • xrpXRP (XRP) $ 3.05
  • tetherTether (USDT) $ 1.00
  • solanaSolana (SOL) $ 238.13
  • bnbBNB (BNB) $ 906.65
  • usd-coinUSDC (USDC) $ 0.999806
  • dogecoinDogecoin (DOGE) $ 0.259933
  • staked-etherLido Staked Ether (STETH) $ 4,516.60
  • tronTRON (TRX) $ 0.348387
  • cardanoCardano (ADA) $ 0.895298
  • wrapped-stethWrapped stETH (WSTETH) $ 5,481.30
  • chainlinkChainlink (LINK) $ 24.44
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,877.31
  • hyperliquidHyperliquid (HYPE) $ 56.37
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 114,898.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.68
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • stellarStellar (XLM) $ 0.394155
  • wrapped-eethWrapped eETH (WEETH) $ 4,861.11
  • avalanche-2Avalanche (AVAX) $ 28.58
  • bitcoin-cashBitcoin Cash (BCH) $ 591.61
  • wethWETH (WETH) $ 4,523.12
  • hedera-hashgraphHedera (HBAR) $ 0.241091
  • leo-tokenLEO Token (LEO) $ 9.60
  • litecoinLitecoin (LTC) $ 115.62
  • crypto-com-chainCronos (CRO) $ 0.256166
  • the-open-networkToncoin (TON) $ 3.19
  • usdsUSDS (USDS) $ 0.999334
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 115,086.00
  • polkadotPolkadot (DOT) $ 4.21
  • whitebitWhiteBIT Coin (WBT) $ 43.73
  • uniswapUniswap (UNI) $ 10.05
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.200333
  • ethenaEthena (ENA) $ 0.768403
  • mantleMantle (MNT) $ 1.58
  • moneroMonero (XMR) $ 276.03
  • aaveAave (AAVE) $ 310.62
  • bitget-tokenBitget Token (BGB) $ 4.91
  • daiDai (DAI) $ 1.00
  • pepePepe (PEPE) $ 0.000011
  • okbOKB (OKB) $ 190.81
  • memecoreMemeCore (M) $ 2.11
  • jito-staked-solJito Staked SOL (JITOSOL) $ 292.52
  • ondo-financeOndo (ONDO) $ 1.09
  • nearNEAR Protocol (NEAR) $ 2.73