Campaign targeting Selenium Grid for cryptomining (Campaign)
ID: a572e270-8e91-5a6c-a278-413bfed5b54f
STIX ID: report--a572e270-8e91-5a6c-a278-413bfed5b54f
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-09-12
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Cado Security Labs identified two active campaigns exploiting unauthenticated Selenium Grid instances to run base64-encoded scripts that deploy reverse shells, proxyjacking tools (IPRoyal Pawns), cryptominers, and UPX-packed ELF binaries; attackers used techniques including disabling shell history, Docker image abuse (Traffmonetizer, WatchTower), PwnKit privilege escalation, Tor-based command-and-control, and cron persistence to maintain access and evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
