logo

CPU_HU: Fileless cryptominer targeting exposed PostgreSQL with over 1.5K victims

ID: be222205-f0c5-5b23-b59b-edc77b19ff30

STIX ID: report--be222205-f0c5-5b23-b59b-edc77b19ff30

Feed Name: Wiz Blog

Threat Score
70/100

Date Published: 2025-03-31

Date Updated: 2026-05-01

...
...

Wiz Threat Research documents a widespread cryptomining campaign (tracked as JINX-0126) abusing exposed PostgreSQL instances with weak credentials to deploy obfuscated Golang binaries and run XMRig-C3 filelessly via memfd; the actor appends unique per-target configurations and uses persistence and masquerading to evade detection, with three wallets and ~1,500+ infected hosts identified, plus detailed IOCs and mitigation/detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.