How Did Aqua Catch a Cryptomining Attack Hiding in Memory?
ID: 8b0ab7a7-735d-5b40-a451-b859e9a02546
STIX ID: report--8b0ab7a7-735d-5b40-a451-b859e9a02546
Feed Name: Aqua Security Blog
Aqua detected and reconstructed a multistage fileless cryptojacking campaign leveraging a Next.js exploit to execute loaders directly in memory (memfd:), unpack packed stages, drop an XMRig miner (sometimes to /tmp), establish persistence via cron/init scripts and SSH keys, and use anti-removal techniques (chattr +i); the report includes file hashes, C2/staging hosts, and recommends enabling runtime enforcement controls (block fileless execution, drift prevention, cryptomining detection and process-level egress controls).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
