logo

SeleniumGreed: Threat actors exploit exposed Selenium Grid services for Cryptomining

ID: a37ac54c-63da-5699-8f67-47cba21ffe44

STIX ID: report--a37ac54c-63da-5699-8f67-47cba21ffe44

Feed Name: Wiz Blog

Threat Score
70/100

Date Published: 2024-07-25

Date Updated: 2026-05-01

...
...

Wiz Research describes an active campaign called “SeleniumGreed” in which attackers abuse publicly exposed Selenium Grid services (often lacking authentication) to run remote Python shells, deploy a modified UPX-packed XMRig miner, and hijack CPU resources; the report includes detailed attack flow, file and network IoCs (hashes, /bin/xm, /bin/wxm, multiple IP:port indicators and TLS fingerprints), MITRE mappings, and recommended mitigations such as enabling authentication, applying network controls, and runtime detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.