Hackers Exploit Misconfigured YARN, Docker, Confluence, Redis Servers for Crypto Mining
ID: ca3bf1e1-7756-5cc7-b831-ebc68d63846e
STIX ID: report--ca3bf1e1-7756-5cc7-b831-ebc68d63846e
Feed Name: The Hacker News
**Spinning YARN** is an active cybercrime campaign exploiting misconfigured and vulnerable cloud-facing services (Apache Hadoop YARN, Docker, Atlassian Confluence, Redis) to gain remote code execution, escape containers, install rootkits and a reverse shell, and ultimately deploy the XMRig cryptocurrency miner; attackers use automated Golang payloads and mass scanning along with evasion techniques (disabling firewalls, clearing history, disabling SELinux, removing cloud security) to maintain persistence and stealth.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
