logo

Soco404 Cryptomining Campaign Exploits PostgreSQL and Cloud Misconfigurations (Campaign)

ID: 48db99b8-dc12-5928-a7a5-89570ae72fec

STIX ID: report--48db99b8-dc12-5928-a7a5-89570ae72fec

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2025-07-23

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Wiz Research describes the Soco404 cryptomining campaign that targets cloud environments by exploiting exposed PostgreSQL instances and vulnerable Apache Tomcat servers to deliver XMRig miners. The threat actor uses evasive techniques (in-memory execution, process masquerading, log wiping), persistence (cron jobs, shell injections, Windows services), and hides payloads in fake Google Sites 404 pages; infrastructure is also linked to fraudulent crypto trading sites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.