logo

SeleniumGreed: Threat actors exploit exposed Selenium Grid services for Cryptomining (Campaign)

ID: 8fb90b5f-86cf-5d59-a37d-8438c77856bc

STIX ID: report--8fb90b5f-86cf-5d59-a37d-8438c77856bc

Feed Name: Wiz Cloud Threat Landscape

Threat Score
65/100

Date Published: 2024-07-25

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Wiz Research identifies an active campaign named SeleniumGreed in which attackers exploit publicly exposed, unauthenticated Selenium Grid services to run remote commands and deploy a modified XMRig cryptominer; attackers use reverse shells, leverage other compromised nodes as C2/mining-proxies, and take advantage of the default lack of authentication on Selenium Grid instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.