logo

Campaign targeting Selenium Grid for cryptomining (Campaign)

ID: a572e270-8e91-5a6c-a278-413bfed5b54f

STIX ID: report--a572e270-8e91-5a6c-a278-413bfed5b54f

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2024-09-12

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Cado Security Labs identified two active campaigns exploiting unauthenticated Selenium Grid instances to run base64-encoded scripts that deploy reverse shells, proxyjacking tools (IPRoyal Pawns), cryptominers, and UPX-packed ELF binaries; attackers used techniques including disabling shell history, Docker image abuse (Traffmonetizer, WatchTower), PwnKit privilege escalation, Tor-based command-and-control, and cron persistence to maintain access and evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.