Exploit Kits, Cryptominers, Proxyjackers: The New Face of Selenium Grid Abuse
ID: 085f1a1c-8cfc-55aa-9f54-a3adc0643a52
STIX ID: report--085f1a1c-8cfc-55aa-9f54-a3adc0643a52
Feed Name: securityonline.info
Cado Security Labs detected two active campaigns exploiting unauthenticated Selenium Grid instances to inject base64-encoded Python payloads that establish command-and-control, drop ELF binaries, and install cryptominers (perfcc) or proxyjacking tools (IPRoyal/Pawns/EarnFM). Attackers used privilege escalation via CVE-2021-4043 (PwnKit), packed binaries with UPX, disabled logging, cleaned artifacts, and abused Docker containers to replace legitimate services, enabling stealthy resource theft and resale of compromised bandwidth as residential proxies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
