• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Friday, September 12, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

Proxyjacking campaign LABRAT targets vulnerable GitLab deployments

17 August 2023
in Mining
Reading Time: 4 mins read
A A
0
Proxyjacking campaign LABRAT targets vulnerable GitLab deployments
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

Researchers from Sysdig are warning of an ongoing attack campaign against vulnerable GitLab servers that results in deployment of cryptojacking and proxyjacking malware. The attacks use cross-platform malware, kernel rootkits, and multiple layers of obfuscation and try to evade detection by abusing legitimate services.

“This operation was much more sophisticated than many of the attacks the Sysdig TRT typically observes,” researchers from security firm Sysdig said in a new report. “Many attackers do not bother with stealth at all, but this attacker took special care when crafting their operation. The stealthy and evasive techniques and tools used in this operation make defense and detection more challenging.”

The attackers behind the attack campaign, which Sysdig has dubbed LABRAT, search for GitLab servers vulnerable to a known critical security issue tracked as CVE-2021-22205. This flaw stems from improper validation of image files when GitLab processes them with ExifTool and can result in remote code execution. It was patched in GitLab in April 2021 in versions 13.8.8, 13.9.6 and 13.10.3, but exploits for it are still actively used in attacks, meaning hackers find enough unpatched servers to justify its use.

Attackers exploit TryCloudflare to gain an advantage

Once they gain remote code execution, the attackers run a curl command to download and execute a malicious script for a command-and-control (C2) server with a trycloudflare.com hostname. TryCloudflare is a free-tier service provided by Cloudflare for users to evaluate various platform features. Attackers have been known to abuse it to obfuscate their actual C2 server location since Cloudflare’s CDN acts as a proxy in between.

Once executed on a system the script checks if the watchdog process is running and tries to kill it, deletes files from previous infections, disables Tencent Cloud and Alibaba defensive measure, downloads additional malicious binaries, sets up new system services, modifies cron jobs to achieve persistence, collects locally stored SSH keys which are then used to perform lateral movement to other systems.

To obfuscate their communication with the C2 servers, the attackers deployed the CloudFlare Tunnel, a powerful traffic tunneling solution that allows users to expose local services through the secure Cloudflare network without changing firewall settings or doing port forwarding. Researchers from GuidePoint Security recently reported an increase in the number of attacks that abused the Cloudflare Tunnel and TryCloudflare.

In some of the attacks, the LABRAT attackers hosted their malicious binaries on a private GitLab server that has been online since September 2022 but has been continuously updated. It’s not clears if the attackers own this server or if it’s a compromised one being misused to host their files.

Across the various LABRAT attacks they investigated, the Sysdig researchers saw the threat actor behind the campaign use multiple off-the-shelf tools. One of them is an open-source tool called Global Socket (GSocket) that allows two systems inside different private networks to communicate with each other without the need of port forwarding. This is achieved through a network of proxies that use encryption and can also route traffic through Tor, making it very hard to discover the other machine.


In this case, GSocket was used as a backdoor through which attackers could remote access the system and issue commands. To achieve persistence and deploy GSocket as a service that starts at system reboot, the attackers tried to exploit the PwnKit (CVE-2021-4034) privilege escalation vulnerability on Linux systems.

The researchers also found evidence that the LABRAT attackers used an open-source rootkit called the hiding-cryptominers-linux-rootkit designed to hide files and processes and their CPU usage and is intended to obscure cryptomining activity.

Related articles

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024

That’s because LABRAT is ultimately a financially driven attack and one of the ways in which the attackers monetized the hacked servers was by deploying a custom variant of the open-source XMRig cryptocurrency mining program. This was deployed by a loader written in the Go programming language that ensured the crypto mining program was deployed as a service that masquerades as the legitimate sshd (SSH daemon) service.

[crypto-donation-box]

A second method of making money for the attackers was by deploying a tool associated with the IPRoyal service that allows users to share their bandwidth with others for a fee by deploying proxy software on their machines. This method of exploiting compromised machines is increasingly common and has been dubbed proxyjacking.

Cryptohopper
ADVERTISEMENT

The researchers also found files associated with another proxy service called ProxyLite. The tool provided by this service is written in .NET Core, which makes it cross platform and it uses some advanced obfuscation techniques that seem to be designed to make detection and analysis harder.

“Crypomining and proxyjacking should never be considered nuisance malware and be written off by having the system rebuilt without a thorough investigation,” the Sysdig researchers warned. “As seen in this operation, malware does have the ability to automatically spread to other systems with SSH keys. We have also seen in the past, with SCARLETEEL, that attackers will install cryptominers, but also steal intellectual property if they have the opportunity.”


The Sysdig report contains various indicators of compromise associated with this ongoing campaign such as file names and hashes, malicious URLs and IP addresses that can be used to build detections.

Source link

Tags: campaigndeploymentsGitLabLABRATProxyjackingTargetsVulnerable
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Conflux Price Prediction: CFX Tumbles 27%

Next Post

SpaceX sold $373M worth of Bitcoin acquired in 2021-2022: Report

Related Posts

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
0

A fake news story circulated today about Russia’s supposed embrace of bitcoin mining and crypto payments. According to excited social...

New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
0

A new report estimates a $20 billion revenue opportunity in Bitcoin BTC/USD mining chips and hardware over the next five...

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

30 July 2024
0

(Bloomberg) -- Russia is moving to regulate the use of cryptocurrencies, as companies wrestle with increasing difficulties in foreign payments...

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

30 July 2024
0

The Russian central bank plans to initiate international payments in cryptocurrencies by the end of the year to overcome delays...

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

30 July 2024
0

Listed both on Wall Street and the London Stock Exchange (LSE) Bitcoin miner Argo Blockchain, has announced a £6.5 million...

Load More
Next Post
SpaceX sold 3M worth of Bitcoin acquired in 2021-2022: Report

SpaceX sold $373M worth of Bitcoin acquired in 2021-2022: Report

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
Dennis Potter Defends Bitcoin’s Low Fees Amid Security Concerns

Dennis Potter Defends Bitcoin’s Low Fees Amid Security Concerns

12 September 2025
Galaxy Digital Buys 2.31 Million Solana Tokens Worth Nearly 6 Million – Yahoo Finance

Galaxy Digital Buys 2.31 Million Solana Tokens Worth Nearly $536 Million – Yahoo Finance

12 September 2025
4 Key Signs Altcoin Season Is Accelerating Fast in September 2025

4 Key Signs Altcoin Season Is Accelerating Fast in September 2025

12 September 2025
BitMine’s Ethereum Holdings Top 2.1 Million After Fresh 46,255 ETH Buy

BitMine’s Ethereum Holdings Top 2.1 Million After Fresh 46,255 ETH Buy

12 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • Dennis Potter Defends Bitcoin’s Low Fees Amid Security Concerns
  • Galaxy Digital Buys 2.31 Million Solana Tokens Worth Nearly $536 Million – Yahoo Finance
  • 4 Key Signs Altcoin Season Is Accelerating Fast in September 2025
  • BitMine’s Ethereum Holdings Top 2.1 Million After Fresh 46,255 ETH Buy
  • FTX, Alameda Redeem $45 Million in Solana From Staking – Cryptonews

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 115,187.00
  • ethereumEthereum (ETH) $ 4,530.19
  • xrpXRP (XRP) $ 3.07
  • tetherTether (USDT) $ 1.00
  • solanaSolana (SOL) $ 237.56
  • bnbBNB (BNB) $ 904.48
  • usd-coinUSDC (USDC) $ 0.999809
  • dogecoinDogecoin (DOGE) $ 0.260120
  • staked-etherLido Staked Ether (STETH) $ 4,523.55
  • tronTRON (TRX) $ 0.348466
  • cardanoCardano (ADA) $ 0.899882
  • wrapped-stethWrapped stETH (WSTETH) $ 5,489.53
  • chainlinkChainlink (LINK) $ 24.60
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,884.30
  • hyperliquidHyperliquid (HYPE) $ 56.51
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 115,032.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.67
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • stellarStellar (XLM) $ 0.397234
  • wrapped-eethWrapped eETH (WEETH) $ 4,869.76
  • avalanche-2Avalanche (AVAX) $ 28.70
  • bitcoin-cashBitcoin Cash (BCH) $ 594.88
  • wethWETH (WETH) $ 4,530.35
  • hedera-hashgraphHedera (HBAR) $ 0.242228
  • leo-tokenLEO Token (LEO) $ 9.59
  • litecoinLitecoin (LTC) $ 115.78
  • crypto-com-chainCronos (CRO) $ 0.256402
  • the-open-networkToncoin (TON) $ 3.20
  • usdsUSDS (USDS) $ 0.999617
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 115,245.00
  • polkadotPolkadot (DOT) $ 4.24
  • whitebitWhiteBIT Coin (WBT) $ 43.79
  • uniswapUniswap (UNI) $ 10.08
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.200418
  • ethenaEthena (ENA) $ 0.773110
  • mantleMantle (MNT) $ 1.59
  • moneroMonero (XMR) $ 275.29
  • aaveAave (AAVE) $ 312.72
  • bitget-tokenBitget Token (BGB) $ 4.92
  • pepePepe (PEPE) $ 0.000011
  • daiDai (DAI) $ 1.00
  • okbOKB (OKB) $ 192.59
  • memecoreMemeCore (M) $ 2.15
  • jito-staked-solJito Staked SOL (JITOSOL) $ 291.99
  • ondo-financeOndo (ONDO) $ 1.10
  • nearNEAR Protocol (NEAR) $ 2.75