logo

How Did Aqua Catch a Cryptomining Attack Hiding in Memory?

ID: 8b0ab7a7-735d-5b40-a451-b859e9a02546

STIX ID: report--8b0ab7a7-735d-5b40-a451-b859e9a02546

Feed Name: Aqua Security Blog

Threat Score
65/100

Date Published: 2026-08-04

Date Updated: 2026-08-10

...
...

Aqua detected and reconstructed a multistage fileless cryptojacking campaign leveraging a Next.js exploit to execute loaders directly in memory (memfd:), unpack packed stages, drop an XMRig miner (sometimes to /tmp), establish persistence via cron/init scripts and SSH keys, and use anti-removal techniques (chattr +i); the report includes file hashes, C2/staging hosts, and recommends enabling runtime enforcement controls (block fileless execution, drift prevention, cryptomining detection and process-level egress controls).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.