• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Thursday, September 11, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

Cryptominers Targeting Misconfigured Apache Hadoop and Flink with Rootkit in New Attacks

12 January 2024
in Mining
Reading Time: 3 mins read
A A
0
Cryptominers Targeting Misconfigured Apache Hadoop and Flink with Rootkit in New Attacks
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

Related articles

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
Cryptohopper
ADVERTISEMENT

Jan 12, 2024NewsroomCryptocurrency / Malware

Cybersecurity researchers have identified a new attack that exploits misconfigurations in Apache Hadoop and Flink to deploy cryptocurrency miners within targeted environments.

“This attack is particularly intriguing due to the attacker’s use of packers and rootkits to conceal the malware,” Aqua security researchers Nitzan Yaakov and Assaf Morag said in an analysis published earlier this week. “The malware deletes contents of specific directories and modifies system configurations to evade detection.”

The infection chain targeting Hadoop leverages a misconfiguration in the YARN’s (Yet Another Resource Negotiator) ResourceManager, which is responsible for tracking resources in a cluster and scheduling applications.

Specifically, the misconfiguration can be exploited by an unauthenticated, remote threat actor to execute arbitrary code by means of a crafted HTTP request, subject to the privileges of the user on the node where the code is executed.

Cybersecurity

The attacks aimed at Apache Flink, likewise, take aim at a misconfiguration that permits a remote attacker to achieve code execution sans any authentication.

These misconfigurations are not novel and have been exploited in the past by financially motivated groups like TeamTNT, which is known for its history of targeting Docker and Kubernetes environments for the purpose of cryptojacking and other malicious activities.

But what makes the latest set of attacks noteworthy is the use of rootkits to hide crypto mining processes after obtaining an initial foothold into Hadoop and Flink applications.

“The attacker sends an unauthenticated request to deploy a new application,” the researchers explained. “The attacker is able to run a remote code by sending a POST request to the YARN, requesting to launch the new application with the attacker’s command.”

The command is purpose-built to clear the /tmp directory of all existing content, fetch a file called “dca” from a remote server, and execute it, followed by deleting all files in the /tmp directory once again.

Cybersecurity

The executed payload is a packed ELF binary that acts as a downloader to retrieve two rootkits and a Monero cryptocurrency miner binary. It’s worth pointing out that various adversaries, including Kinsing, have resorted to employing rootkits to conceal the presence of the mining process.

To achieve persistence, a cron job is created to download and execute a shell script that deploys the ‘dca’ binary. Further analysis of the threat actor’s infrastructure reveals that the staging server used to fetch the downloader was registered on October 31, 2023.

As mitigations, it’s recommended that organizations deploy agent-based security solutions to detect cryptominers, rootkits, obfuscated or packed binaries, as well as other suspicious runtime behaviors.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.



Source link

[crypto-donation-box]
Tags: ApacheAttacksCryptominersFlinkHadoopMisconfiguredRootkitTargeting
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Expert Says War Over XRP Non-Security Status Is Officially Over

Next Post

Dogecoin (DOGE) & Polkadot (DOT) Suffer From Market Volatility

Related Posts

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
0

A fake news story circulated today about Russia’s supposed embrace of bitcoin mining and crypto payments. According to excited social...

New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
0

A new report estimates a $20 billion revenue opportunity in Bitcoin BTC/USD mining chips and hardware over the next five...

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

30 July 2024
0

(Bloomberg) -- Russia is moving to regulate the use of cryptocurrencies, as companies wrestle with increasing difficulties in foreign payments...

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

30 July 2024
0

The Russian central bank plans to initiate international payments in cryptocurrencies by the end of the year to overcome delays...

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

30 July 2024
0

Listed both on Wall Street and the London Stock Exchange (LSE) Bitcoin miner Argo Blockchain, has announced a £6.5 million...

Load More
Next Post
Dogecoin (DOGE) & Polkadot (DOT) Suffer From Market Volatility

Dogecoin (DOGE) & Polkadot (DOT) Suffer From Market Volatility

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
Solana Treasury Firms Boost Holdings to 6.5M SOL as Upexi Posts 126% Surge – Yahoo Finance

Solana Treasury Firms Boost Holdings to 6.5M SOL as Upexi Posts 126% Surge – Yahoo Finance

11 September 2025
SharpLink Transfers 379M USDC To Galaxy Digital: Ethereum Buy Incoming?

SharpLink Transfers 379M USDC To Galaxy Digital: Ethereum Buy Incoming?

11 September 2025
Galaxy's Novogratz calls it the 'season of SOL', says Solana is tailor made for financial markets – The Block

Galaxy's Novogratz calls it the 'season of SOL', says Solana is tailor made for financial markets – The Block

11 September 2025
Can CPI Rates Drive Market Sentiment-Bitcoin and Altcoins Poised for a Massive Price Action

Can CPI Rates Drive Market Sentiment-Bitcoin and Altcoins Poised for a Massive Price Action

11 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • Solana Treasury Firms Boost Holdings to 6.5M SOL as Upexi Posts 126% Surge – Yahoo Finance
  • SharpLink Transfers 379M USDC To Galaxy Digital: Ethereum Buy Incoming?
  • Galaxy's Novogratz calls it the 'season of SOL', says Solana is tailor made for financial markets – The Block
  • Can CPI Rates Drive Market Sentiment-Bitcoin and Altcoins Poised for a Massive Price Action
  • 78,229 Ethereum Leaves Kraken As 4 New Wallets Move ETH: Institutional Accumulation?

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 115,264.00
  • ethereumEthereum (ETH) $ 4,455.38
  • xrpXRP (XRP) $ 3.03
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 902.37
  • solanaSolana (SOL) $ 228.25
  • usd-coinUSDC (USDC) $ 0.999812
  • dogecoinDogecoin (DOGE) $ 0.256317
  • staked-etherLido Staked Ether (STETH) $ 4,446.07
  • tronTRON (TRX) $ 0.346560
  • cardanoCardano (ADA) $ 0.893062
  • wrapped-stethWrapped stETH (WSTETH) $ 5,396.46
  • chainlinkChainlink (LINK) $ 24.37
  • hyperliquidHyperliquid (HYPE) $ 56.55
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,800.54
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 115,073.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.66
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • stellarStellar (XLM) $ 0.394820
  • avalanche-2Avalanche (AVAX) $ 29.19
  • wrapped-eethWrapped eETH (WEETH) $ 4,789.81
  • bitcoin-cashBitcoin Cash (BCH) $ 596.54
  • wethWETH (WETH) $ 4,454.53
  • hedera-hashgraphHedera (HBAR) $ 0.239168
  • leo-tokenLEO Token (LEO) $ 9.62
  • litecoinLitecoin (LTC) $ 116.00
  • crypto-com-chainCronos (CRO) $ 0.259064
  • the-open-networkToncoin (TON) $ 3.19
  • usdsUSDS (USDS) $ 0.999801
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 115,222.00
  • polkadotPolkadot (DOT) $ 4.24
  • whitebitWhiteBIT Coin (WBT) $ 43.72
  • uniswapUniswap (UNI) $ 10.00
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • mantleMantle (MNT) $ 1.67
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.198911
  • ethenaEthena (ENA) $ 0.778329
  • moneroMonero (XMR) $ 271.09
  • aaveAave (AAVE) $ 309.03
  • bitget-tokenBitget Token (BGB) $ 4.92
  • pepePepe (PEPE) $ 0.000011
  • daiDai (DAI) $ 0.999267
  • okbOKB (OKB) $ 194.90
  • nearNEAR Protocol (NEAR) $ 2.75
  • bittensorBittensor (TAO) $ 357.84
  • jito-staked-solJito Staked SOL (JITOSOL) $ 280.54
  • ondo-financeOndo (ONDO) $ 1.06