logo

CPU_HU: Malicious Campaign Targeting Misconfigured PostgreSQL Servers for Cryptomining (Incident)

ID: 84c6c7bc-c1e1-5747-9730-8974d23b4af9

STIX ID: report--84c6c7bc-c1e1-5747-9730-8974d23b4af9

Feed Name: Wiz Cloud Threat Landscape

Threat Score
65/100

Date Published: 2025-02-27

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

The provided markdown contains a Linux shell script that kills processes associated with security and known malware (e.g., kinsing, kdevtmpfsi), then attempts to download a payload from 159.223.123.175 using curl/wget or a custom /dev/tcp HTTP GET fallback, saving it as 'pg_core', and appends an encoded blob to 'postmaster'—behavior consistent with an automated malware dropper/install routine.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.