InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: Exposed Selenium Grid servers targeted for cryptomining and proxyjacking
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > Exposed Selenium Grid servers targeted for cryptomining and proxyjacking
Technology

Exposed Selenium Grid servers targeted for cryptomining and proxyjacking

September 15, 2024 3 Min Read
Share
Crypto Mining and Proxyjacking
SHARE

Selenium Grid instances exposed to the internet have been targeted by bad actors for illicit cryptocurrency mining and proxyjacking campaigns.

“Selenium Grid is a server that makes it easy to run test cases in parallel across different browsers and versions,” Cado Security researchers Tara Gould and Nate Bill wrote in an analysis published today.

“However, Selenium Grid’s default configuration lacks authentication, making it vulnerable to exploitation by threat actors.”

The act of exploiting publicly accessible Selenium Grid instances to deploy cryptocurrency miners was previously noted by cloud security firm Wiz in late July 2024 as part of a cluster of activity dubbed SeleniumGreed.

Cado said it has observed two separate attacks against its honeypot servers, with threat actors exploiting the lack of authentication protections to carry out a range of malicious activities.

The first one utilizes the “goog:chromeOptions” dictionary to inject a Base64-encoded Python script, then retrieves a script named “y”, which is an open-source GSocket reverse shell.

Cryptomining and Proxyjacking

The reverse shell then acts as a medium to introduce the next stage payload, a bash script named “pl” that uses curl and wget commands to retrieve IPRoyal Pawn and EarnFM from a remote server.

“IPRoyal Pawns is a residential proxy service that allows users to sell their internet bandwidth in exchange for money,” Cado said.

“Users’ internet connections are shared with the IPRoyal network and the service uses bandwidth as a residential proxy, making it available for a variety of purposes, including malicious ones.”

EarnFM is also a proxyware solution that is being touted as a “groundbreaking” way to generate passive income online simply by sharing your internet connection.

See also  Iranian Cyber ​​Group OilRig Targets Iraqi Government with Advanced Malware Attack

The second attack follows the same route as the proxyjacking campaign, delivering a bash script via a Python script that checks if it is being run on a 64-bit machine before dropping a Golang-based ELF binary.

The ELF file then attempts to escalate to root privileges by exploiting a PwnKit vulnerability (CVE-2021-4043) and drops an XMRig cryptocurrency miner called perfcc.

“Many organizations utilize Selenium Grid for web browser testing, and this attack further highlights how misconfigured instances can be exploited by threat actors,” the researchers said. “Users should ensure that authentication is configured, as authentication is not enabled by default.”

Share This Article
Twitter Copy Link
Previous Article King Arthur roguelike Sworn is basically a co-op version of Hades, and I'm hooked King Arthur roguelike Sworn is basically a co-op version of Hades, and I’m hooked
Next Article The Pope accused Harris and Trump of taking "anti-life" positions and urged Catholics to vote for the "lesser evil." The Pope accused Harris and Trump of taking “anti-life” positions and urged Catholics to vote for the “lesser evil.”
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest News

The Solution is Cyber ​​Hygiene

The Solution is Cyber ​​Hygiene

Cybersecurity in healthcare has never been more urgent. As the…

September 19, 2024
mm

Enterprise LLM API: A top choice for powering LLM applications in 2024

Some big recent news stories have escalated the race for…

September 19, 2024
Authentication Bypass

GitLab fixes critical SAML authentication bypass vulnerability in CE and EE editions

GitLab has released a patch to address a critical flaw…

September 19, 2024
Chinese engineer indicted in US for years of cyberespionage targeting NASA and military

Chinese engineer indicted in US for years of cyberespionage targeting NASA and military

A Chinese national has been indicted in the United States…

September 19, 2024
IoT Botnet

New “Raptor Train” IoT Botnet Compromises Over 200,000 Devices Worldwide

Cybersecurity researchers have discovered a never-before-seen botnet made up of…

September 18, 2024

You Might Also Like

Google Workspace
Technology

How to investigate ChatGPT activity in Google Workspace

5 Min Read
Designing Identity-Focused Incident Response Playbooks
Technology

Designing Identity-Focused Incident Response Playbooks

2 Min Read
insighthubnews
Technology

From Atari to Doom: How Google is redefining video games with AI

9 Min Read
mm
Technology

Reflection 70B: LLM with Self-Correcting Cognition and Initiative Performance

11 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?