Misconfigured Jenkins Servers Used for Cryptomining (Campaign)
ID: 921d177d-4a3c-5048-b587-707ba0236a7c
STIX ID: report--921d177d-4a3c-5048-b587-707ba0236a7c
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-07-05
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Researchers observed attackers exploiting misconfigured Jenkins Script Consoles to gain remote code execution and deploy cryptocurrency miners. The malicious scripts search writable directories, download and decrypt miner binaries, kill competing high-CPU processes, and maintain persistence via cron jobs and systemd-run; many publicly exposed Jenkins servers (per Shodan) increase the attack surface. Remediation recommends identifying indicators of compromise, removing malicious files, and redeploying workloads from known clean states.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
