logo

mem Malware with Runtime Security

ID: ac0f54de-52c8-5f32-bcf4-c2a0a3b75371

STIX ID: report--ac0f54de-52c8-5f32-bcf4-c2a0a3b75371

Feed Name: Aqua Security Blog

Threat Score
75/100

Date Published: 2025-06-11

Date Updated: 2026-04-26

...
...

The Aqua blog warns that numerous internet-exposed PostgreSQL servers (estimated 850,000–1.6 million) are being targeted by botnets and threat actors (e.g., Kinsing, PGMiner, PG_MEM) that exploit weak/default credentials to install malware such as the stealthy pg_mem, which mimics legitimate Postgres processes and uses persistence and evasion techniques; it recommends enabling behavioral detection and runtime enforcement in Aqua to detect and block such activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.