CPU_HU: Malicious Campaign Targeting Misconfigured PostgreSQL Servers for Cryptomining (Incident)
ID: 84c6c7bc-c1e1-5747-9730-8974d23b4af9
STIX ID: report--84c6c7bc-c1e1-5747-9730-8974d23b4af9
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-02-27
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
The provided markdown contains a Linux shell script that kills processes associated with security and known malware (e.g., kinsing, kdevtmpfsi), then attempts to download a payload from 159.223.123.175 using curl/wget or a custom /dev/tcp HTTP GET fallback, saving it as 'pg_core', and appends an encoded blob to 'postmaster'—behavior consistent with an automated malware dropper/install routine.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
