logo

Misconfigured Selenium Grid servers abused for Monero mining

ID: e332bb4a-a6d6-567f-b2f2-4a55c3040220

STIX ID: report--e332bb4a-a6d6-567f-b2f2-4a55c3040220

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-07-28

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

Researchers at Wiz report an active campaign called "SeleniumGreed" that abuses unauthenticated Selenium Grid instances to run base64-encoded Python scripts through the WebDriver API, open reverse shells, and deploy a modified XMRig Monero miner; attackers exploit default configurations and a sudo-enabled 'seluser', use compromised nodes as C2 and mining proxies, and have identified roughly 30,000 exposed instances, creating resource-impacting cryptomining and potential footholds for further malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.