Cryptominers Targeting Misconfigured Apache Hadoop and Flink with Rootkit in New Attacks
ID: aba569fe-46f5-5a7a-90ac-57219453b535
STIX ID: report--aba569fe-46f5-5a7a-90ac-57219453b535
Feed Name: The Hacker News
Aqua Security researchers uncovered a campaign abusing misconfigured Apache Hadoop YARN ResourceManager and Apache Flink instances to perform unauthenticated remote code execution via crafted HTTP requests; the payload is a packed ELF downloader that fetches two rootkits and a Monero cryptocurrency miner, uses cron jobs for persistence, and wipes /tmp to evade detection. The attackers employ packers and rootkits to conceal mining processes; mitigations recommended include agent-based detection for cryptominers, rootkits, packed/obfuscated binaries, and suspicious runtime behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
