logo

Exposed Jupyter Notebooks Targeted for Cryptomining (Campaign)

ID: 37403e65-bc51-5987-9920-320abc6f229a

STIX ID: report--37403e65-bc51-5987-9920-320abc6f229a

Feed Name: Wiz Cloud Threat Landscape

Threat Score
65/100

Date Published: 2025-03-16

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Cado Security Labs identified a cryptomining campaign exploiting misconfigured Jupyter Notebooks to deploy multi-stage miners on Windows and Linux. Attackers retrieve MSI or script-based loaders that execute masqueraded binaries (e.g., java.exe), download and decrypt payloads (ChaCha20), persist via cron jobs or PHP loaders, and host components on public repositories such as GitHub and Gitee; the final payloads mine cryptocurrencies including Monero and Sumokoin.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.