logo

PG_MEM Malware Exploiting Misconfigured PostreSQL Instances (Campaign)

ID: c4ae11a2-d939-55fc-9497-9f42b9a6025b

STIX ID: report--c4ae11a2-d939-55fc-9497-9f42b9a6025b

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2024-08-19

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers discovered PG_MEM, a malware family that brute-forces weak PostgreSQL credentials to create superuser roles, deploy two payloads, persist via PostgreSQL command execution, evade detection, remove competing malware, and mine cryptocurrency on compromised hosts. The campaign exploits misconfigured Postgres instances and weak passwords to achieve persistence and resource abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.