logo

Cryptominers Targeting Misconfigured Apache Hadoop and Flink with Rootkit in New Attacks

ID: aba569fe-46f5-5a7a-90ac-57219453b535

STIX ID: report--aba569fe-46f5-5a7a-90ac-57219453b535

Feed Name: The Hacker News

Threat Score
68/100

Date Published: 2024-01-12

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Aqua Security researchers uncovered a campaign abusing misconfigured Apache Hadoop YARN ResourceManager and Apache Flink instances to perform unauthenticated remote code execution via crafted HTTP requests; the payload is a packed ELF downloader that fetches two rootkits and a Monero cryptocurrency miner, uses cron jobs for persistence, and wipes /tmp to evade detection. The attackers employ packers and rootkits to conceal mining processes; mitigations recommended include agent-based detection for cryptominers, rootkits, packed/obfuscated binaries, and suspicious runtime behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.