• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Friday, September 12, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

Hackers Targeting WebLogic Servers and Docker APIs for Mining Cryptocurrencies

16 September 2022
in Mining
Reading Time: 5 mins read
A A
0
Hackers Targeting WebLogic Servers and Docker APIs for Mining Cryptocurrencies
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

Related articles

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024

Malicious actors such as Kinsing are taking advantage of both recently disclosed and older security flaws in Oracle WebLogic Server to deliver cryptocurrency-mining malware.

Cybersecurity company Trend Micro said it found the financially-motivated group leveraging the vulnerability to drop Python scripts with capabilities to disable operating system (OS) security features such as Security-Enhanced Linux (SELinux), and others.

The operators behind the Kinsing malware have a history of scanning for vulnerable servers to co-opt them into a botnet, including that of Redis, SaltStack, Log4Shell, Spring4Shell, and the Atlassian Confluence flaw (CVE-2022-26134).

CyberSecurity

The Kinsing actors have also been involved in campaigns against container environments via misconfigured open Docker Daemon API ports to launch a crypto miner and subsequently spread the malware to other containers and hosts.

The latest wave of attacks entails the actor weaponizing CVE-2020-14882 (CVSS score: 9.8), a two-year-old remote code execution (RCE) bug, against unpatched servers to seize control of the server and drop malicious payloads.

It’s worth noting that the vulnerability has been exploited in the past by multiple botnets to distribute Monero miners and the Tsunami backdoor on infected Linux systems.

Successful exploitation of the flaw was succeeded by the deployment of a shell script that’s responsible for a series of actions: Removing the /var/log/syslog system log, turning off security features and cloud service agents from Alibaba and Tencent, and killing competing miner processes.

The shell script then proceeds to download the Kinsing malware from a remote server, while also taking steps to ensure persistence by means of cron job.

“The successful exploitation of this vulnerability can lead to RCE, which can allow attackers to perform a plethora of malicious activities on affected systems,” Trend Micro said. “This can range from malware execution […] to theft of critical data, and even complete control of a compromised machine.”

TeamTNT actors make a comeback with the Kangaroo Attack

The development comes as researchers from Aqua Security identified three new attacks linked to another “vibrant” cryptojacking group called TeamTNT, which voluntarily shut shop in November 2021.

“TeamTNT has been scanning for a misconfigured Docker Daemon and deploying alpine, a vanilla container image, with a command line to download a shell script (k.sh) to a C2 server,” Aqua Security researcher Assaf Morag said.

What’s notable about the attack chain is that it appears to be designed to break SECP256K1 encryption, which, if successful, could give the actor the ability to calculate the keys to any cryptocurrency wallet. Put differently, the idea is to leverage the high but illegal computational power of its targets to run the ECDLP solver and get the key.

CyberSecurity

Two other attacks mounted by the group entail the exploitation of exposed Redis servers and misconfigured Docker APIs to deploy coin miners and Tsunami binaries.

TeamTNT’s targeting of Docker REST APIs has been well-documented over the past year. But in an operational security blunder spotted by Trend Micro, credentials associated with two of the attacker-controlled DockerHub accounts have been uncovered.

The accounts – alpineos and sandeep078 – are said to have been used to distribute a variety of malicious payloads like rootkits, Kubernetes exploit kits, credential stealers, XMRig Monero miners, and even the Kinsing malware.

“The account alpineos was used in exploitation attempts on our honeypots three times, from mid-September to early October 2021, and we tracked the deployments’ IP addresses to their location in Germany,” Trend Micro’s Nitesh Surana said.

“The threat actors were logged in to their accounts on the DockerHub registry and probably forgot to log out.” Alternatively, “the threat actors logged in to their DockerHub account using the credentials of alpineos.”

Trend Micro said the malicious alpineos image had been downloaded more than 150,000 times, adding it notified Docker about these accounts.

It’s also recommending organizations to configure the exposed REST API with TLS to mitigate adversary-in-the-middle (AiTM) attacks, as well as use credential stores and helpers to host user credentials.



Source link

Cryptohopper
ADVERTISEMENT
[crypto-donation-box]
Tags: APIscryptocurrenciesDockerHackersMiningServersTargetingWebLogic
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Shiba Inu ($SHIB) Lead Developer Says the Team Is Focused on Partnerships and Not Hype

Next Post

Ethereum Merge Has Tied Ether Futures Activity to Staking Yields, Traders Say

Related Posts

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
0

A fake news story circulated today about Russia’s supposed embrace of bitcoin mining and crypto payments. According to excited social...

New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
0

A new report estimates a $20 billion revenue opportunity in Bitcoin BTC/USD mining chips and hardware over the next five...

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

30 July 2024
0

(Bloomberg) -- Russia is moving to regulate the use of cryptocurrencies, as companies wrestle with increasing difficulties in foreign payments...

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

30 July 2024
0

The Russian central bank plans to initiate international payments in cryptocurrencies by the end of the year to overcome delays...

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

30 July 2024
0

Listed both on Wall Street and the London Stock Exchange (LSE) Bitcoin miner Argo Blockchain, has announced a £6.5 million...

Load More
Next Post
Ethereum Merge Has Tied Ether Futures Activity to Staking Yields, Traders Say

Ethereum Merge Has Tied Ether Futures Activity to Staking Yields, Traders Say

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
Dennis Potter Defends Bitcoin’s Low Fees Amid Security Concerns

Dennis Potter Defends Bitcoin’s Low Fees Amid Security Concerns

12 September 2025
Galaxy Digital Buys 2.31 Million Solana Tokens Worth Nearly 6 Million – Yahoo Finance

Galaxy Digital Buys 2.31 Million Solana Tokens Worth Nearly $536 Million – Yahoo Finance

12 September 2025
4 Key Signs Altcoin Season Is Accelerating Fast in September 2025

4 Key Signs Altcoin Season Is Accelerating Fast in September 2025

12 September 2025
BitMine’s Ethereum Holdings Top 2.1 Million After Fresh 46,255 ETH Buy

BitMine’s Ethereum Holdings Top 2.1 Million After Fresh 46,255 ETH Buy

12 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • Dennis Potter Defends Bitcoin’s Low Fees Amid Security Concerns
  • Galaxy Digital Buys 2.31 Million Solana Tokens Worth Nearly $536 Million – Yahoo Finance
  • 4 Key Signs Altcoin Season Is Accelerating Fast in September 2025
  • BitMine’s Ethereum Holdings Top 2.1 Million After Fresh 46,255 ETH Buy
  • FTX, Alameda Redeem $45 Million in Solana From Staking – Cryptonews

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 115,187.00
  • ethereumEthereum (ETH) $ 4,530.19
  • xrpXRP (XRP) $ 3.07
  • tetherTether (USDT) $ 1.00
  • solanaSolana (SOL) $ 237.56
  • bnbBNB (BNB) $ 904.48
  • usd-coinUSDC (USDC) $ 0.999809
  • dogecoinDogecoin (DOGE) $ 0.260120
  • staked-etherLido Staked Ether (STETH) $ 4,523.55
  • tronTRON (TRX) $ 0.348466
  • cardanoCardano (ADA) $ 0.899882
  • wrapped-stethWrapped stETH (WSTETH) $ 5,489.53
  • chainlinkChainlink (LINK) $ 24.60
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,884.30
  • hyperliquidHyperliquid (HYPE) $ 56.51
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 115,032.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.67
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • stellarStellar (XLM) $ 0.397234
  • wrapped-eethWrapped eETH (WEETH) $ 4,869.76
  • avalanche-2Avalanche (AVAX) $ 28.70
  • bitcoin-cashBitcoin Cash (BCH) $ 594.88
  • wethWETH (WETH) $ 4,530.35
  • hedera-hashgraphHedera (HBAR) $ 0.242228
  • leo-tokenLEO Token (LEO) $ 9.59
  • litecoinLitecoin (LTC) $ 115.78
  • crypto-com-chainCronos (CRO) $ 0.256402
  • the-open-networkToncoin (TON) $ 3.20
  • usdsUSDS (USDS) $ 0.999617
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 115,245.00
  • polkadotPolkadot (DOT) $ 4.24
  • whitebitWhiteBIT Coin (WBT) $ 43.79
  • uniswapUniswap (UNI) $ 10.08
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.200418
  • ethenaEthena (ENA) $ 0.773110
  • mantleMantle (MNT) $ 1.59
  • moneroMonero (XMR) $ 275.29
  • aaveAave (AAVE) $ 312.72
  • bitget-tokenBitget Token (BGB) $ 4.92
  • pepePepe (PEPE) $ 0.000011
  • daiDai (DAI) $ 1.00
  • okbOKB (OKB) $ 192.59
  • memecoreMemeCore (M) $ 2.15
  • jito-staked-solJito Staked SOL (JITOSOL) $ 291.99
  • ondo-financeOndo (ONDO) $ 1.10
  • nearNEAR Protocol (NEAR) $ 2.75