logo

PG_MEM: A Malware Hidden in the Postgres Processes

ID: 97d31523-8413-57e8-8498-274d76a1b84a

STIX ID: report--97d31523-8413-57e8-8498-274d76a1b84a

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2024-08-19

Date Updated: 2026-05-12

...
...

Aqua Nautilus researchers describe PG_MEM, a campaign that brute-forces internet-exposed PostgreSQL servers to create superuser roles, execute shell commands via COPY ... FROM PROGRAM, and deploy multiple packed ELF binaries (pg_core, pg_mem, memory) that install an XMRig cryptominer and establish persistence (cron) while removing competing malware and artifacts; the report provides observed IOCs (IP 128.199.77.96, MD5 hashes), attack flow, detection guidance, and MITRE ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.