logo

Exploit Kits, Cryptominers, Proxyjackers: The New Face of Selenium Grid Abuse

ID: 085f1a1c-8cfc-55aa-9f54-a3adc0643a52

STIX ID: report--085f1a1c-8cfc-55aa-9f54-a3adc0643a52

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2024-09-17

Date Updated: 2026-04-22

Author: do son

...
...

Cado Security Labs detected two active campaigns exploiting unauthenticated Selenium Grid instances to inject base64-encoded Python payloads that establish command-and-control, drop ELF binaries, and install cryptominers (perfcc) or proxyjacking tools (IPRoyal/Pawns/EarnFM). Attackers used privilege escalation via CVE-2021-4043 (PwnKit), packed binaries with UPX, disabled logging, cleaned artifacts, and abused Docker containers to replace legitimate services, enabling stealthy resource theft and resale of compromised bandwidth as residential proxies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.