logo

Hackers Exploiting Jenkins Script Console for Cryptocurrency Mining Attacks

ID: f8e09a45-9f0d-515d-a09b-d959e6876433

STIX ID: report--f8e09a45-9f0d-515d-a09b-d959e6876433

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2024-07-09

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Trend Micro researchers discovered that misconfigured Jenkins Script Console endpoints exposed on the Internet can be abused to achieve remote code execution; attackers have used a Base64-encoded Groovy script to deploy a cryptocurrency miner (hosted on berrystore.me), establish persistence, and manage CPU usage. The report warns administrators to enforce authentication and authorization, audit instances, and avoid publicly exposing Jenkins to mitigate this active threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.