DevOps Tools Targeted for Cryptojacking
ID: 8190b682-c325-5dd0-ae8d-10a42021e74b
STIX ID: report--8190b682-c325-5dd0-ae8d-10a42021e74b
Feed Name: Wiz Blog
Threat Score
Wiz Threat Research documents an active cryptojacking campaign attributed to the actor JINX-0132 that leverages misconfigurations and known vulnerabilities in Nomad, Consul, Docker API, and Gitea to remotely execute and deploy the off-the-shelf XMRig Monero miner; the report details attack payloads, observed indicators (including a Monero wallet and XMRig release), scale of exposed services, and provides prevention and detection guidance for affected DevOps services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
