Hackers Proxyjack & Cryptomine Selenium Grid Servers
ID: 74b63fa8-d7b0-5953-9584-42294dd63177
STIX ID: report--74b63fa8-d7b0-5953-9584-42294dd63177
Feed Name: Dark Reading
Threat actors are actively scanning and compromising Internet-exposed Selenium Grid servers to deploy proxyware (IPRoyal Pawn, EarnFM) and cryptominers (perfcc/XMRig), leveraging scripts, the GSocket toolkit for C2, and an exploit for PwnKit (CVE-2021-4043). Cado Security's honeypot observed rapid automated attacks within 24 hours, and prior scans indicate tens of thousands of Selenium Grid instances are publicly accessible and often outdated, enabling large-scale proxyjacking, cryptomining, and potential escalation into production systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
