logo

Hackers Proxyjack & Cryptomine Selenium Grid Servers

ID: 74b63fa8-d7b0-5953-9584-42294dd63177

STIX ID: report--74b63fa8-d7b0-5953-9584-42294dd63177

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-09-12

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Threat actors are actively scanning and compromising Internet-exposed Selenium Grid servers to deploy proxyware (IPRoyal Pawn, EarnFM) and cryptominers (perfcc/XMRig), leveraging scripts, the GSocket toolkit for C2, and an exploit for PwnKit (CVE-2021-4043). Cado Security's honeypot observed rapid automated attacks within 24 hours, and prior scans indicate tens of thousands of Selenium Grid instances are publicly accessible and often outdated, enabling large-scale proxyjacking, cryptomining, and potential escalation into production systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.