• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Friday, September 12, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

New LABRAT Campaign Exploits GitLab Flaw for Cryptojacking and Proxyjacking Activities

17 August 2023
in Mining
Reading Time: 3 mins read
A A
0
New LABRAT Campaign Exploits GitLab Flaw for Cryptojacking and Proxyjacking Activities
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

Related articles

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024

Aug 17, 2023THNCryptojacking / Proxyjacking

A new, financially motivated operation dubbed LABRAT has been observed weaponizing a now-patched critical flaw in GitLab as part of a cryptojacking and proxyjacking campaign.

“The attacker utilized undetected signature-based tools, sophisticated and stealthy cross-platform malware, command-and-control (C2) tools which bypassed firewalls, and kernel-based rootkits to hide their presence,” Sysdig said in a report shared with The Hacker News.

“Furthermore, the attacker abused a legitimate service, TryCloudflare, to obfuscate their C2 network.”

Proxyjacking allows the attacker to rent the compromised host out to a proxy network, making it possible to monetize the unused bandwidth. Cryptojacking, on the other hand, refers to the abuse of the system resources to mine cryptocurrency.

A notable aspect of the campaign is the use of compiled binaries written in Go and .NET to fly under the radar, with LABRAT also providing backdoor access to the infected systems. This could ultimately pave the way for follow-on attack, data theft, and ransomware.

Cybersecurity

The attack chains begin with the exploitation of CVE-2021-22205 (CVSS score: 10.0), a remote code execution vulnerability that has been exploited in the wild by Indonesian-origin actors in the past to deploy crypto miners.

A successful break-in is followed by the retrieval of a dropper shell script from a C2 server that sets up persistence, conducts lateral movement using SSH credentials found in the system, and downloads additional binaries from a private GitLab repository.

“During the LABRAT operation, TryCloudflare was used to redirect connections to a password-protected web server that hosted a malicious shell script,” Miguel Hernández said. “Using the legitimate TryCloudFlare infrastructure can make it difficult for defenders to identify subdomains as malicious, especially if it is used in normal operations too.”

TryCloudflare is a free tool that can be used to create a Cloudflare Tunnel without adding a site to Cloudflare’s DNS. It launches a process that generates a random subdomain on trycloudflare.com, thereby allowing internal resources to be exposed to the public internet.

Cybersecurity

The development adds to the abuse of cloudflared to establish covert communication channels from compromised hosts and main access to victim networks.

In a second variant of the attack, the adversary is said to have used a Solr server instead of TryCloudflare to download an exploit for the PwnKit (CVE-2021-4034) from the same GitLab repository to elevate privileges, along with another file that’s no longer accessible.

Some of the payloads retrieved by the dropper script include an open-source utility known as Global Socket (gsocket) for remote access and binaries to conduct cryptojacking and proxyjacking via known services such as IPRoyal and ProxyLite. The mining process is concealed using a kernel-based rootkit called hiding-cryptominers-linux-rootkit.

Also delivered is a Go-based executable designed to ensure persistence and kill competing mining processes or older versions of itself in order to fully harness the machine’s resources and maximize their earnings.

“Since the goal of the LABRAT operation is financial, time is money,” Hernández said. “The longer a compromise goes undetected, the more money the attacker makes and the more it will cost the victim.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.



Source link

Cryptohopper
ADVERTISEMENT
[crypto-donation-box]
Tags: ActivitiescampaignCryptoJackingExploitsFlawGitLabLABRATProxyjacking
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Google Bard predicts XRP price in the next crypto bull market

Next Post

Tether CTO Paolo Ardoino says Bitcoin mining needs better analytical tools

Related Posts

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
0

A fake news story circulated today about Russia’s supposed embrace of bitcoin mining and crypto payments. According to excited social...

New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
0

A new report estimates a $20 billion revenue opportunity in Bitcoin BTC/USD mining chips and hardware over the next five...

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

30 July 2024
0

(Bloomberg) -- Russia is moving to regulate the use of cryptocurrencies, as companies wrestle with increasing difficulties in foreign payments...

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

30 July 2024
0

The Russian central bank plans to initiate international payments in cryptocurrencies by the end of the year to overcome delays...

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

30 July 2024
0

Listed both on Wall Street and the London Stock Exchange (LSE) Bitcoin miner Argo Blockchain, has announced a £6.5 million...

Load More
Next Post
Tether CTO Paolo Ardoino says Bitcoin mining needs better analytical tools

Tether CTO Paolo Ardoino says Bitcoin mining needs better analytical tools

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
Dennis Potter Defends Bitcoin’s Low Fees Amid Security Concerns

Dennis Potter Defends Bitcoin’s Low Fees Amid Security Concerns

12 September 2025
Galaxy Digital Buys 2.31 Million Solana Tokens Worth Nearly 6 Million – Yahoo Finance

Galaxy Digital Buys 2.31 Million Solana Tokens Worth Nearly $536 Million – Yahoo Finance

12 September 2025
4 Key Signs Altcoin Season Is Accelerating Fast in September 2025

4 Key Signs Altcoin Season Is Accelerating Fast in September 2025

12 September 2025
BitMine’s Ethereum Holdings Top 2.1 Million After Fresh 46,255 ETH Buy

BitMine’s Ethereum Holdings Top 2.1 Million After Fresh 46,255 ETH Buy

12 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • Dennis Potter Defends Bitcoin’s Low Fees Amid Security Concerns
  • Galaxy Digital Buys 2.31 Million Solana Tokens Worth Nearly $536 Million – Yahoo Finance
  • 4 Key Signs Altcoin Season Is Accelerating Fast in September 2025
  • BitMine’s Ethereum Holdings Top 2.1 Million After Fresh 46,255 ETH Buy
  • FTX, Alameda Redeem $45 Million in Solana From Staking – Cryptonews

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 115,187.00
  • ethereumEthereum (ETH) $ 4,530.19
  • xrpXRP (XRP) $ 3.07
  • tetherTether (USDT) $ 1.00
  • solanaSolana (SOL) $ 237.56
  • bnbBNB (BNB) $ 904.48
  • usd-coinUSDC (USDC) $ 0.999809
  • dogecoinDogecoin (DOGE) $ 0.260120
  • staked-etherLido Staked Ether (STETH) $ 4,523.55
  • tronTRON (TRX) $ 0.348466
  • cardanoCardano (ADA) $ 0.899882
  • wrapped-stethWrapped stETH (WSTETH) $ 5,489.53
  • chainlinkChainlink (LINK) $ 24.60
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,884.30
  • hyperliquidHyperliquid (HYPE) $ 56.51
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 115,032.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.67
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • stellarStellar (XLM) $ 0.397234
  • wrapped-eethWrapped eETH (WEETH) $ 4,869.76
  • avalanche-2Avalanche (AVAX) $ 28.70
  • bitcoin-cashBitcoin Cash (BCH) $ 594.88
  • wethWETH (WETH) $ 4,530.35
  • hedera-hashgraphHedera (HBAR) $ 0.242228
  • leo-tokenLEO Token (LEO) $ 9.59
  • litecoinLitecoin (LTC) $ 115.78
  • crypto-com-chainCronos (CRO) $ 0.256402
  • the-open-networkToncoin (TON) $ 3.20
  • usdsUSDS (USDS) $ 0.999617
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 115,245.00
  • polkadotPolkadot (DOT) $ 4.24
  • whitebitWhiteBIT Coin (WBT) $ 43.79
  • uniswapUniswap (UNI) $ 10.08
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.200418
  • ethenaEthena (ENA) $ 0.773110
  • mantleMantle (MNT) $ 1.59
  • moneroMonero (XMR) $ 275.29
  • aaveAave (AAVE) $ 312.72
  • bitget-tokenBitget Token (BGB) $ 4.92
  • pepePepe (PEPE) $ 0.000011
  • daiDai (DAI) $ 1.00
  • okbOKB (OKB) $ 192.59
  • memecoreMemeCore (M) $ 2.15
  • jito-staked-solJito Staked SOL (JITOSOL) $ 291.99
  • ondo-financeOndo (ONDO) $ 1.10
  • nearNEAR Protocol (NEAR) $ 2.75